-= Per source details. Do not edit below this line.=-
Package exfiltrates the environment variables during the import
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-09-amzn-sagemaker-studio
Reasons (based on the campaign):
exfiltration-env-variables
dependency-confusion
{
"iocs": {
"domains": [
"gauss-security.com"
],
"urls": [
"https://gauss-security.com/poca.php"
]
},
"malicious-packages-origins": [
{
"source": "kam193",
"modified_time": "2025-09-07T16:39:45.13294Z",
"id": "pypi/2025-09-amzn-sagemaker-studio/amzn-sagemaker-studio",
"sha256": "36c198a080b9cee5e67f0b4d799ba2de868fdf4619fe4fcf1a2088a3972d9ace",
"versions": [
"0.1.0"
],
"import_time": "2025-12-02T22:30:54.901430981Z"
},
{
"source": "kam193",
"modified_time": "2025-09-07T16:39:45.13294Z",
"id": "pypi/2025-09-amzn-sagemaker-studio/amzn-sagemaker-studio",
"sha256": "a557d275cca7627fa4d3e2c72f0fc9b78fc5ac70aa87a0ab586f1abf9f8777a6",
"versions": [
"0.1.0"
],
"import_time": "2025-12-02T23:07:17.945724095Z"
}
]
}