-= Per source details. Do not edit below this line.=-
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-standard-pypi-install-pentest
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
The package overrides the install command in setup.py to execute malicious code during installation.
{
"malicious-packages-origins": [
{
"source": "kam193",
"modified_time": "2024-07-26T16:53:30Z",
"sha256": "e87fd99c50d754e4a0de0d4694123e2ea1c7cea2b3fe0e7cf38e4ca14847557a",
"id": "pypi/GENERIC-standard-pypi-install-pentest/oe-extract-ids",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:56.264374418Z"
},
{
"source": "kam193",
"modified_time": "2024-07-26T16:53:30Z",
"sha256": "bebbe22a538c4b7b6688bd82facdd749052e801663cf523c8d9c1eb11f81ea57",
"id": "pypi/GENERIC-standard-pypi-install-pentest/oe-extract-ids",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:19.449911565Z"
},
{
"versions": [
"0.1.40",
"0.1",
"0.1.50",
"1.5.0",
"1.5.1"
],
"modified_time": "2024-07-26T16:53:30Z",
"sha256": "5e3a9da53a43e9f5f826582915787b7709a1fc06d85e816dff426da3a6f01feb",
"id": "pypi/GENERIC-standard-pypi-install-pentest/oe-extract-ids",
"source": "kam193",
"import_time": "2025-12-10T21:38:58.564013706Z"
},
{
"versions": [
"0.1",
"0.1.40",
"0.1.50",
"1.5.0",
"1.5.1"
],
"modified_time": "2024-07-26T16:53:30Z",
"sha256": "5fbe8e0c51aeab8ce5ba91e81cbd65171044eed3a45c701e312862fddfa26cf5",
"id": "pypi/GENERIC-standard-pypi-install-pentest/oe-extract-ids",
"source": "kam193",
"import_time": "2025-12-30T22:39:04.325075632Z"
}
]
}