A malicious package named 'defi-hunter' was uploaded to the Python Package Index (PyPI), introducing a remote code execution (RCE) vulnerability in open-source DeFi (Decentralized Finance) security analysis toolkits. This affects any users or systems consuming the compromised package, enabling attackers to execute arbitrary code on vulnerable hosts. Immediate removal and inspection of affected environments are critical.