Malicious packages
Malware feed
Every package version published with malicious code, federated from OSV.dev's MAL-* feed: GitHub malware advisories, Snyk, PyPI removed-malware, OSS-Fuzz, and others. These are not CVE-style vulnerabilities — they're intentionally malicious uploads (typosquats, compromised maintainer tokens, worm-style campaigns like Shai-Hulud).
Recent advisories
11,178 total in pypi · sorted newest first- Feb 9, 2023
Malicious code in freqtade (PyPI)
- Feb 9, 2023
Malicious code in cxt (PyPI)
- Feb 9, 2023
Malicious code in ccx (PyPI)
- Feb 9, 2023
Malicious code in cccxt (PyPI)
- Feb 9, 2023
Malicious code in ccxtt (PyPI)
- Feb 9, 2023
Malicious code in ccxxt (PyPI)
- Jan 1, 2023
Malicious code in fredli (PyPI)
1 compromised version
- Jan 1, 2023
Malicious code in fredmi (PyPI)
1 compromised version
- Aug 30, 2022
Malicious code in winrpcexploit (PyPI)
- Aug 30, 2022
Malicious code in browserdiv (PyPI)
- Aug 30, 2022
Malicious code in zlibsrc (PyPI)
- Aug 30, 2022
Malicious code in free-net-vpn2 (PyPI)
- Aug 30, 2022
Malicious code in free-net-vpn (PyPI)
- Aug 30, 2022
Malicious code in test-async (PyPI)
- Aug 30, 2022
Malicious code in pyproto2 (PyPI)
- Aug 30, 2022
Malicious code in pymocks (PyPI)
- Aug 30, 2022
Malicious code in pyg-utils (PyPI)
- Aug 30, 2022
Malicious code in ascii2text (PyPI)
- May 31, 2022
Malicious code in rrequests (PyPI)
- May 31, 2022
Malicious code in reuests (PyPI)
- May 31, 2022
Malicious code in requuests (PyPI)
- May 31, 2022
Malicious code in requestts (PyPI)
- May 31, 2022
Malicious code in requessts (PyPI)
- May 31, 2022
Malicious code in requess (PyPI)
- May 31, 2022
Malicious code in requeests (PyPI)
- May 31, 2022
Malicious code in reqquests (PyPI)
- May 31, 2022
Malicious code in reequests (PyPI)
- May 31, 2022
Malicious code in equests (PyPI)
Page 224 of 224