---
id: MAL-2026-10869
title: Malicious code in paperclip-ai (PyPI)
summary: Malicious code in paperclip-ai (PyPI)
severity: none
vendor: paperclip-ai
product: paperclip-ai
ecosystem: pip
affected:
  - paperclip-ai
published: '2026-07-20'
updated: '2026-07-20'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-10869'
references:
  - url: >-
      https://github.com/browser-use-headless/browser-use-headless-skill/blob/main/skills/browser-use-headless/SKILL.md?plain=1#L19
  - url: 'https://bad-packages.kam193.eu/pypi/package/paperclip-ai'
tags:
  - osv
  - pip
ingestedAt: '2026-07-20T13:32:44.846Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (643de4cab1ea2f7becbca5a7dead46fcb39f35596d2bf7a371fdd2c82ded1530)
A clone of a legitimate package with added code that exfiltrates env variables and multiple sensitive files: credentials, dotenv, shell history, etc. Exfiltrated credentials were quickly validated by the attacker.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-07-browser-use-headless


Reasons (based on the campaign):


 - files-exfiltration


 - exfiltration-env-variables


 - exfiltration-credentials


 - clones-real-package


## Affected packages

- `paperclip-ai`

## Remediation

Refer to the advisory for the patched release.
