Supply-chain threat intelligence
Risk score
92
Indexed incident for veloxml-cli (pypi).
-= Per source details. Do not edit below this line.=-
The package advertises fake functionality and exfiltrates the given email and basic information about the host when used.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-veloxml-cli
Reasons (based on the campaign):
action-hidden-in-lib-usage
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
Affected versions
Indicators
Timeline