-= Per source details. Do not edit below this line.=-
Generic campaign for all (likely) research / pentests, where the amount or art of collected data raises questions about the privacy, security and ethical side.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: GENERIC-questionable-pentest
Reasons (based on the campaign):
exfiltration-env-variables
exfiltration-generic
The package overrides the install command in setup.py to execute malicious code during installation.
typosquatting
{
"malicious-packages-origins": [
{
"sha256": "8989214aa2d7a1235632c53b0687389dd88b8a52d4a23019650c9fea9eb3d3f1",
"id": "RLMA-2025-05617",
"source": "reversing-labs",
"modified_time": "2025-12-01T12:54:38Z",
"versions": [
"1337.0.0"
],
"import_time": "2025-12-02T09:09:38.169590369Z"
},
{
"sha256": "b50880a5309c35fe5630fe38e39600cceb622b1a69e28191b9653baac29da09b",
"id": "pypi/GENERIC-questionable-pentest/libtasnl",
"source": "kam193",
"modified_time": "2025-10-22T12:26:36.131668Z",
"versions": [
"1337.0.0"
],
"import_time": "2025-12-02T22:30:55.311583051Z"
},
{
"sha256": "0da2df30cd680f292df7b195f51829e4afc94604336223d58b0bfca92714d9fc",
"id": "pypi/GENERIC-questionable-pentest/libtasnl",
"source": "kam193",
"modified_time": "2025-10-22T12:26:36.131668Z",
"versions": [
"1337.0.0"
],
"import_time": "2025-12-02T23:07:18.33813094Z"
},
{
"sha256": "8489f165dd9360f9b9535bb908a6831c2ab05d453a66b3dcd889f7796fd6e377",
"id": "RLUA-2026-00473",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:15:37Z",
"import_time": "2026-03-19T12:19:59.759555447Z"
}
]
}