Logo
pypi

termncolor@3.1.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:45 PM UTC

Malicious

OSV ID

MAL-2025-47454

Ecosystem

pypi

Summary

This package is malicious and allows an attack remote code execution on Windows and Linux machines. The package termncolor uses colorinal as a dependency. The package colorinal contains the malicious behavior.

Source: google-open-source-security (bdc043b163e4ec6acada5d376a6a7becb3bba51c2b25307833500ec9fd8e1c4f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.