-= Per source details. Do not edit below this line.=-
This package is malicious and typosquating the legitimate pyspellchecker library. This package will deploy a remote-access trojan that allows the attacker full control of the victim's host.
{
"iocs": {
"domains": [
"dothebest.store"
],
"urls": [
"dothebest.store/allow/inform.php",
"dothebest.store/refresh.php"
]
},
"malicious-packages-origins": [
{
"sha256": "c83520810b148ec74e509b16851a1fafa1bec576b502a5debabd9b52520d9754",
"modified_time": "2025-12-01T23:33:02Z",
"import_time": "2025-12-01T23:34:06.5476Z",
"versions": [
"1.4.0"
],
"source": "google-open-source-security",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
]
}
]
}