updateuuid4@0.1.2
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:45 PM UTC
OSV ID
MAL-2025-191917
Ecosystem
pypi
Summary
The package, with an innocent looking name, has as the only functionality reporting to a Telegram channel given username and password. The functionality is in the "HeadersUpdate" class, that also looks like attempting to look innocent. The code does nothing more than reporting given credentials through a bot using the name "hitlercute_bot". --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-02-updateuuid4 Reasons (based on the campaign): - infostealer
Source: kam193 (2c45f904631a26aae94cafeeac5ea0f7efe0fc5d4f46dea48da17dcb766111d5)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.