Logo
pypi

aitextkit-py@0.1.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC

Malicious

OSV ID

MAL-2026-16130

Ecosystem

pypi

Summary

The package presents itself as a small text-cleaning utility library, but both shipped implementation modules (text.py and system.py) consist of a single-line pyobfuscator.com loader of the form _ = lambda __: __import__('zlib').decompress(__import__('base64').b64decode(__[::-1]));exec((_)(b'...')), which reverses, base64-decodes, zlib-decompresses, and exec()s an opaque blob at module import. __init__.py imports from.text, so import aitextkit runs the decoded bytes on the installer's Python interpreter. __init__.py also re-exports an undocumented setup symbol whose body lives inside the obfuscated blob and which is not mentioned in the README, tests, or public API documentation - a common stager entry-point shape. system.py, which backs the documented get_os_version() helper, uses the identical loader and its tests reference platform, release, and arch fields, so the decoded code at minimum performs host enumeration inside code that is not inspectable from source. The declared text-utility purpose has no legitimate need to ship its entire implementation as an exec-decoded blob; the loader shape matches that used by PyPI credential-stealer families.

Source: amazon-inspector (47e96f519e8acba48a6f7760b37a9ad70b94bfbf79fb5eac4fc682849b2837e3)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.