pypi

robloxextra @0.8

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2025-6578

Ecosystem

pypi

Summary

Importing the module starts downloading multiple stages of obfuscated code, that e.g. adds itself to autostart. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-06-robloxextra Reasons (based on the campaign): - typosquatting - Downloads and executes a remote malicious script. - obfuscation - peristence-autorun

Source: kam193 (d4281a22f488970ba086ca475848dedc3db41f77d760a4c280356d1018480ccf)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.