pypi

python-socket-test @2.0.1

Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 1:35 PM UTC

Malicious

OSV ID

MAL-2025-3460

Ecosystem

pypi

Summary

Importing the package starts a script that takes commands from remote server and executes locally --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-python-socket-test Reasons (based on the campaign): - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

Source: kam193 (93a8d30e631680bace9b05db1ac189cbcc472895fcfb1db40f4df52f301a6599)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.