Supply-chain threat intelligence
Risk score
92
Indexed incident for yolov8mini (pypi).
On importing the module, there is an automated start of a Telegram bot capable of exfiltrating passwords from browsers, executing arbitrary commands and so on. While the description states it's a monitoring tool, the automated start, capabilities targeting secret values suggest malicious intentions.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-03-yolov8mini
Reasons (based on the campaign):
infostealer
exfiltration-generic
dependency-confusion
exfiltration-browser-data
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
Indicators
Timeline