-= Per source details. Do not edit below this line.=-
Package attempts to load in an obfuscated way a code from a file (not included in the package) as well as inject a dynamic library to the Python dynamic libs directories.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-07-jython-file
Reasons (based on the campaign):
modify-system-without-consent
obfuscation
{
"malicious-packages-origins": [
{
"id": "pypi/2025-07-jython-file/jython-file",
"import_time": "2025-12-02T22:30:55.290668139Z",
"modified_time": "2025-07-07T09:14:37Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "8d77188ac0d4b558f8f4e150d8d2ad48b0014ee54dce2038c3805a6268cde605",
"source": "kam193"
},
{
"id": "pypi/2025-07-jython-file/jython-file",
"import_time": "2025-12-02T23:07:18.315308155Z",
"modified_time": "2025-07-07T09:14:37Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "fc56f6ba4b75b25d4289c3aa3cb1d05f9b1d7bbfacf00b11e270d76ba87a1a3e",
"source": "kam193"
},
{
"id": "pypi/2025-07-jython-file/jython-file",
"import_time": "2025-12-10T21:38:57.560273908Z",
"modified_time": "2025-07-07T09:14:37Z",
"sha256": "ee9867ffff34d570006ef0456a9108963b8ee67dc85559c72501474550f1622c",
"source": "kam193",
"versions": [
"0.999999999",
"0.9999999999",
"1.99999999999"
]
}
]
}