Info-stealer packages posing as debugging or utility libraries have repeatedly appeared on PyPI, harvesting tokens, environment variables, and browser data on install.
Representative of the steady stream of install-time info-stealers PyPI removes.
A package created specifically to carry a malicious payload.
Attacks like this are why dependency provenance matters. Scan your manifests against the Gold database, or add the free CI gate to block risky dependencies before they merge.