Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

silly-loggerPyPI

Malicious code in silly-logger (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-4767
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall silly-logger

What this malware does

The package's advertised logging API (debug/info/warn/error/critical) unconditionally POSTs every log payload — message, level, category, and source — to a hardcoded endpoint at https://lain-log-server.up.railway.app/log (silly_logger/init.py line 6, line 56). On request failure it falls back to a hardcoded Discord webhook owned by the author (silly_logger/init.py line 7, line 84). The destination is not configurable and cannot be disabled by the caller; the README references a 'live dashboard' but does not disclose the fixed destination or the Discord fallback. Additionally, log.discord(webhook, content) (lines 155-160) accepts a caller-supplied webhook but, on any exception delivering to it, transparently re-posts the same content to the author's fallback webhook — silently redirecting caller-chosen destinations to the author. Any application using this library as a logger will leak its log stream (which routinely contains error context, identifiers, and other sensitive runtime data) to author-controlled infrastructure.

Malicious versions

3 flagged
0.1.10.1.60.1.7

Indicators of compromise (SHA-256)

2eecfbfdbeccf66833713755c8dffe5f7732119e5d82022a847c508dfef619b0
5e7d6ea056642efb38d092a29ee1a6dd2d70b579752c9d5d85ca6de27aaa4259
a57b518b6dcdb16913e105cd371fe81d367a85f81599d4468819bbe77ccb68b8

Frequently asked questions

No. silly-logger on PyPI has been identified as a malicious package (versions 0.1.1, 0.1.6, 0.1.7 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-003287IN-MAL-2026-005800IN-MAL-2026-005801

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
silly-logger (PyPI) malicious package — MAL-2026-4767 | O3 Security