-= Per source details. Do not edit below this line.=-
This package is malicious and typosquating the legitimate pyspellchecker library. This package will deploy a remote-access trojan that allows the attacker full control of the victim's host.
{
"iocs": {
"domains": [
"dothebest.store"
],
"urls": [
"dothebest.store/allow/inform.php",
"dothebest.store/refresh.php"
]
},
"malicious-packages-origins": [
{
"sha256": "56df7571e75ad7e85850f9a34bb482f19466af4481db56951ffba42475a4238d",
"modified_time": "2025-12-02T00:36:12Z",
"import_time": "2025-12-02T00:36:18.91202Z",
"versions": [
"1.0.1"
],
"source": "google-open-source-security",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
]
}
]
}