pypi

utf-cleaner @3.4.2

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 12:32 PM UTC

Malicious

OSV ID

MAL-2025-73

Ecosystem

pypi

Summary

During import, the package silently downloads and executes remote code. This code starts a web server in the separate process and listens for commands to execute from a C2 server, as well as periodically sends a beacon to C2 allowing discovery and finishing execution. This package is closely related to Github repository https://github.com/xcummins/tg-outline-seller/ from the same author, where it's used as dependency effectively compromising its users. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-old-utf-cleaner Reasons (based on the campaign): - Downloads and executes a remote malicious script. - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

Source: kam193 (09b9e5c5deafbf756df5201976fdbdc3c61c10e815234df9aeb32764a3cd9652)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.