sinontop-utils @0.3.5
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 4:33 PM UTC
OSV ID
MAL-2025-6586
Ecosystem
pypi
Summary
Series of packages mostly with an obfuscated infostealer attempting to collect Chrome data. While discord webhook is usually set to an example, there are other, correct uploading URLs Some of related packages only test partial malicious code, like webhooks from overwritten setup.py --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-07-0x9xnx Reasons (based on the campaign): - infostealer - obfuscation - exfiltration-browser-data - exfiltration-crypto - The package overrides the install command in setup.py to execute malicious code during installation.
Source: kam193 (2e4796f9772fd88b2cad42713f8d9b731428bea0bc0aaef2645676789636b7c1)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.