pypi
Malicioustermncolor@3.1.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:45 PM UTC
OSV ID
MAL-2025-47454
Ecosystem
pypi
Summary
This package is malicious and allows an attack remote code execution on Windows and Linux machines. The package termncolor uses colorinal as a dependency. The package colorinal contains the malicious behavior.
Source: google-open-source-security (bdc043b163e4ec6acada5d376a6a7becb3bba51c2b25307833500ec9fd8e1c4f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.