pypi
Maliciousplp-contract@2.0.2
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 3:37 AM UTC
OSV ID
MAL-2026-13711
Ecosystem
pypi
Summary
No install-time, import-time, or runtime code paths were identified that read installer secrets, fetch or execute remote code, relay caller data to third-party destinations, or establish persistence. No lifecycle hooks with network I/O and no hardcoded exfiltration endpoints are present.
Source: amazon-inspector (8e3ef373acec23f98bde23ab356fd83a31773db1aa9a01ec2505775893e990fb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.