VDB
Sign up

MAL-2026-16356

Malicious code in starlette-healthchecks (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (13c2438df5dfe3675f8861c03c803a273747135af8a70fc916235ad64d6cd22f) The package appears to be a typosquatting research attempt. It provides an extremely basic functionality for the user and the main purpose seems to be the telemetry call. Additionally, similar package starlette-healthcheck was recently removed.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-starlette-healthcheck

Reasons (based on the campaign):

- action-hidden-in-lib-usage

- typosquatting

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/starlette-healthchecks

No fixed version published yet for starlette-healthchecks (pip). Pin to a known-safe version or switch to an alternative.

References