pypi

thisismytest @5.0.0

Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 3:36 PM UTC

Malicious

OSV ID

MAL-2026-2017

Ecosystem

pypi

Summary

During installation, the package downloads and runs a remote executable, which is identified as a backdoor. It connects with a remote server and executes basic commands --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-thisismytest Reasons (based on the campaign): - malware - Downloads and executes a remote executable. - backdoor

Source: kam193 (a1c269bbb834081025da993697e3e2e44db4a97e16e21f4c792ed85391772fa9)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.