MAL-2026-16356
Malicious code in starlette-healthchecks (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (13c2438df5dfe3675f8861c03c803a273747135af8a70fc916235ad64d6cd22f) The package appears to be a typosquatting research attempt. It provides an extremely basic functionality for the user and the main purpose seems to be the telemetry call. Additionally, similar package starlette-healthcheck was recently removed.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-starlette-healthcheck
Reasons (based on the campaign):
- action-hidden-in-lib-usage
- typosquatting
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for starlette-healthchecks (pip). Pin to a known-safe version or switch to an alternative.