rasterkit @1.0.4
Vulnerability report · Last retrieved from osv.dev July 23, 2026 at 9:18 AM UTC
OSV ID
MAL-2026-10974
Ecosystem
pypi
Summary
This package is a clone of Pillow library with malicious code hidden in an image using steganography. The code is the used in a dependant package to install an SSH backdoor. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-textwrap-toolkit-stager Reasons (based on the campaign): - backdoor - obfuscation - crypto-related - Downloads and executes a remote malicious script. - exfiltration-crypto
Source: kam193 (a6eea31746baa37e55a76fec564eda1852839be005d53ae1e24bf2b9ea4c7875)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.