pypi

upllib @1.0

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 4:33 PM UTC

Malicious

OSV ID

MAL-2024-11736

Ecosystem

pypi

Summary

When importing the module and a specific file exists in the current directory, obfuscated code downloads and starts the next stage of obfuscated code (cstealer infostealer) --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-10-pyutiltool Reasons (based on the campaign): - infostealer - obfuscation - infostealer:cstealer

Source: kam193 (6207428c93f872f851e291726fc7a7384f9226b903c01a5a3f1545f82d66bf0b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.