-= Per source details. Do not edit below this line.=-
On importing the module, the code attempts to span a reverse shell. In the current version, the remote domain does not exist
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-04-flask-auth-sys
Reasons (based on the campaign):
dependency-confusion
The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
obfuscation
{
"iocs": {
"domains": [
"beacon.kubershell.io"
]
},
"malicious-packages-origins": [
{
"sha256": "c934eee6779ff735799b39b4a5355c0931e30914a49500afd183f066ec4af683",
"id": "pypi/2025-04-flask-auth-sys/flask-auth-system",
"source": "kam193",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2025-04-02T19:54:07Z",
"import_time": "2025-12-02T22:30:55.199319103Z"
},
{
"sha256": "debc87eb7af33e5146831c7e1b8ff69ccdebe2c9bbf353216c719b10ebe8431c",
"id": "pypi/2025-04-flask-auth-sys/flask-auth-system",
"source": "kam193",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2025-04-02T19:54:07Z",
"import_time": "2025-12-02T23:07:18.20850607Z"
},
{
"sha256": "83c824d3eff87fd20e3730c2d2b3cc52987ba4fb1e667448e35b453679c5bbd6",
"id": "pypi/2025-04-flask-auth-sys/flask-auth-system",
"source": "kam193",
"modified_time": "2025-04-02T19:54:07Z",
"import_time": "2025-12-10T21:38:57.493576433Z",
"versions": [
"0.0.1",
"0.0.2"
]
}
]
}