-= Per source details. Do not edit below this line.=-
This is a clone of "pymunk" package. In the space.py file there is a code that attempts to exfiltrate data from the Discord client during initialization. L101:129
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-12-piepunk
Reasons (based on the campaign):
exfiltration-generic
infostealer
clones-real-package
action-hidden-in-lib-usage
{
"malicious-packages-origins": [
{
"modified_time": "2024-12-19T21:59:33Z",
"import_time": "2025-12-02T22:30:55.428770954Z",
"sha256": "2150fce5d17537377c902711664078bdb143099946e2105018a4a43fedd84d87",
"source": "kam193",
"id": "pypi/2024-12-piepunk/piepunk",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"modified_time": "2024-12-19T21:59:33Z",
"import_time": "2025-12-02T23:07:18.454048771Z",
"sha256": "40c9660a52e99412daf32818f5263ad562bf43281984b9676aa93874912132be",
"source": "kam193",
"id": "pypi/2024-12-piepunk/piepunk",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"modified_time": "2024-12-19T21:59:33Z",
"import_time": "2025-12-10T21:38:57.669292263Z",
"versions": [
"6.9.0",
"6.9.1",
"6.9.3"
],
"source": "kam193",
"id": "pypi/2024-12-piepunk/piepunk",
"sha256": "9c4476825aac01ea124ed0d6dede2b4183df8485af01036d7c35e19e4b3982a9"
}
]
}