pypi
Maliciousveilcord-tls@0.0.7.6
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC
OSV ID
MAL-2025-47458
Ecosystem
pypi
Summary
This package decodes a payload and executes it whenever it is imported. It seems to be targeting veilcord package users. Its contents are almost identical to veilcord, except for the addition of the malicious payload.
Source: oracle-using-macaron (aed8328880d0c346cc1c0c9d51602617be4ea88a7a23878b68164484949555b2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.