Logo
pypi

spo365-graph@1.1.2

Vulnerability report · Last retrieved from osv.dev October 1, 2026 at 9:21 PM UTC

Malicious

OSV ID

MAL-2026-17421

Ecosystem

pypi

Summary

During installation, the package deploys a rogue AWS Lambda function to collect credentials from Secret Manager as well as collect other data. Data are then exfiltrated. The malicious code was introduced in version 1.1.2. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-10-spo365-graph Reasons (based on the campaign): - The package overrides the install command in setup.py to execute malicious code during installation. - exfiltration-cloud-tokens - targetted-attack - exfiltration-credentials

Source: kam193 (ea8dd7600717964f4ca8f8b1134f867f4bf69f1538243d5c7da752eefed99fe1)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.