-= Per source details. Do not edit below this line.=-
Clearly a demo malicious package, attempting to exfiltrate a token from the git config
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2024-10-old-maliciouspackage
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"source": "kam193",
"modified_time": "2024-10-15T16:27:48Z",
"sha256": "a17fbba816fdf42b4bdac0d9a16ad4ec7dacfbc367a4f57bfd936d2239b88917",
"id": "pypi/2024-10-old-maliciouspackage/maliciouspackage",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:56.187097696Z"
},
{
"source": "kam193",
"modified_time": "2024-10-15T16:27:48Z",
"sha256": "d0e8a8d581266436f0546b5039ee82ab734d45f8489e281322dd871124dad9ce",
"id": "pypi/2024-10-old-maliciouspackage/maliciouspackage",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:19.369386127Z"
},
{
"versions": [
"0.5",
"0.4",
"0.3",
"0.2",
"0.1"
],
"modified_time": "2024-10-15T16:27:48Z",
"sha256": "1829cac32365b4cacd5c304a6efc6a7bab4e65f48c7e7f3fc2d598a2e62a5715",
"id": "pypi/2024-10-old-maliciouspackage/maliciouspackage",
"source": "kam193",
"import_time": "2025-12-10T21:38:58.494899691Z"
},
{
"versions": [
"0.1",
"0.2",
"0.3",
"0.4",
"0.5"
],
"modified_time": "2024-10-15T16:27:48Z",
"sha256": "1a98553a381d9f9e235b782ea1a5f5d1c66e903d32df86b73588abc2070143bd",
"id": "pypi/2024-10-old-maliciouspackage/maliciouspackage",
"source": "kam193",
"import_time": "2025-12-30T22:39:04.309907126Z"
}
]
}