-= Per source details. Do not edit below this line.=-
Generic campaign for all (likely) research / pentests, where the amount or art of collected data raises questions about the privacy, security and ethical side.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: GENERIC-questionable-pentest
Reasons (based on the campaign):
exfiltration-env-variables
exfiltration-generic
The package overrides the install command in setup.py to execute malicious code during installation.
typosquatting
{
"malicious-packages-origins": [
{
"sha256": "b3dac5dfd9f2bf5f95ad7a7588b51d247f703eb4e881afd67bc6f53b046be708",
"source": "kam193",
"modified_time": "2024-09-06T11:29:16Z",
"id": "pypi/GENERIC-questionable-pentest/pwnstar-lib",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.451529597Z"
},
{
"sha256": "0b5a94b7cc47cb91bf552abe43f1a0d078ed5c6e668c5ff4caa8c4d9f6d14177",
"source": "kam193",
"modified_time": "2024-09-06T11:29:16Z",
"id": "pypi/GENERIC-questionable-pentest/pwnstar-lib",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.474820214Z"
},
{
"sha256": "ea6fc7d7146c4ac70dab83c40b4d4095fdba3bd615db80fba2860d655083940b",
"source": "kam193",
"modified_time": "2024-09-06T11:29:16Z",
"id": "pypi/GENERIC-questionable-pentest/pwnstar-lib",
"versions": [
"1.5",
"1.6",
"1.7",
"1.8",
"1.9",
"2.0",
"2.1",
"2.3",
"2.4"
],
"import_time": "2025-12-10T21:38:57.691316501Z"
}
]
}