Logo
pypi

uvhttp-custom@1.9.9

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-15863

Ecosystem

pypi

Summary

setup.py contains an obfuscated payload of the form (lambda __: exec(__import__('base64').b64decode('...').decode()))(None) alongside an otherwise-benign setuptools import. The decoded payload writes a bundled script.ps1 to disk and invokes powershell -ExecutionPolicy Bypass -File script.ps1. The PowerShell script uses System.Net.WebClient.DownloadFile to fetch a Windows executable from cdn.discordapp.com/attachments/1532996358427115552/1539384056284717066/enlisted_launcher_1.0.3.190-movn8hpfe.exe into %TEMP%\file.exe and launches it via Start-Process with -WindowStyle Hidden. No hash or signature verification is performed. The payload also invokes os.system("calc"). Running pip install uvhttp-custom on Windows therefore causes the installer's machine to download and silently execute an opaque, unsigned binary from an anonymous Discord CDN URL.

Source: amazon-inspector (bf8bf69e0edd8a79c920c35d2c49e722b38d801c07401dfb673bdb1beb6ea3fc)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.