-= Per source details. Do not edit below this line.=-
A dependency is declared as installable from a webhook service, demonstrating a possibility to inject malicious dependency.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2024-08-install-from-webhook
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"sha256": "15ac0475854dce25a3f13309a2c6aed420cba9e2e2b1f600e325801236d4a20d",
"source": "kam193",
"modified_time": "2024-08-22T22:38:04Z",
"id": "pypi/2024-08-install-from-webhook/bananaholder",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.875334124Z"
},
{
"sha256": "75eb68c36b36e5abf8c54609a124590a23d388ef04d2825da3bd83f8e90c7f46",
"source": "kam193",
"modified_time": "2024-08-22T22:38:04Z",
"id": "pypi/2024-08-install-from-webhook/bananaholder",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:19.058734542Z"
},
{
"sha256": "0ecb4648bc0f306ce53ca0f7a7068af4b8095e564f949dc1f66cf856d9867869",
"source": "kam193",
"modified_time": "2024-08-22T22:38:04Z",
"id": "pypi/2024-08-install-from-webhook/bananaholder",
"versions": [
"0.0.110"
],
"import_time": "2025-12-10T21:38:58.198320025Z"
}
]
}