-= Per source details. Do not edit below this line.=-
This is a copy of a legit package with added basic exfiltration in the setup.py
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-standard-pypi-install-pentest
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
The package overrides the install command in setup.py to execute malicious code during installation.
{
"malicious-packages-origins": [
{
"sha256": "be860829dcedc2bf0981c76c1ea75b885957e544a964d28cf69695e3ee2ac9ed",
"id": "RLMA-2025-05615",
"source": "reversing-labs",
"modified_time": "2025-12-01T12:54:37Z",
"versions": [
"2.1",
"2.2",
"2.3"
],
"import_time": "2025-12-02T09:09:38.069277714Z"
},
{
"sha256": "a8ac8a9f87c9d93340528329867082207c0437ad9fe6d31408cf7754b5705ad9",
"id": "pypi/GENERIC-standard-pypi-install-pentest/lbank-connector-pythons",
"source": "kam193",
"modified_time": "2025-10-22T12:45:32.237742Z",
"versions": [
"2.3",
"2.2",
"2.0"
],
"import_time": "2025-12-02T22:30:56.166875864Z"
},
{
"sha256": "8e2d03134723d75ab2f0b36c6acad54fa5d16b4ba0f04bf2705e188fd19626b9",
"id": "pypi/GENERIC-standard-pypi-install-pentest/lbank-connector-pythons",
"source": "kam193",
"modified_time": "2025-10-22T12:45:32.237742Z",
"versions": [
"2.3",
"2.2",
"2.0"
],
"import_time": "2025-12-02T23:07:19.348565492Z"
},
{
"sha256": "50f436f344f514099ea2389611705259c9094e8f2f6a0faf819c43aa71987599",
"id": "pypi/GENERIC-standard-pypi-install-pentest/lbank-connector-pythons",
"source": "kam193",
"modified_time": "2025-10-22T12:45:32.237742Z",
"versions": [
"2.0",
"2.2",
"2.3"
],
"import_time": "2025-12-30T22:39:04.304135483Z"
},
{
"sha256": "4582809a7633a72953e4b02ed264609834dec8a8df6efab777fb50fc9d0db89e",
"id": "RLUA-2026-00466",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:15:34Z",
"versions": [
"2.0"
],
"import_time": "2026-03-19T12:19:59.123910507Z"
}
]
}