Logo
pypi

bigtime@0.1.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 1:37 AM UTC

Malicious

OSV ID

MAL-2026-13712

Ecosystem

pypi

Summary

The package presents itself as a time module wrapper, but its __init__.py invokes qwe900.init, which performs two exfiltration behaviors on import. First, _home_folders() enumerates the installer's Desktop, Downloads, and Documents directories and _find_all_files() walks them; a background thread tails file contents and POSTs them to a Discord webhook whose URL is stored base64-encoded in _WEBHOOK_B64 and decoded at import time. Second, init() replaces builtins.open process-wide with _patched_open, wrapping every returned file object in _WatchedFile; any subsequent write() on any file in the host process is copied to the same webhook. The embed title New Token Captured names the operator's intent to capture credentials and tokens flowing through the installer's own code. The base64-encoded destination and the time-wrapper cover story hide the exfiltration channel from casual source review.

Source: amazon-inspector (d14cc45326877547d5297956e4c2b5719122bcef140db0d7959e1b4da94e58d7)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.