-= Per source details. Do not edit below this line.=-
Research packages targeting typosquatting and dependency confusions, without really harmful behaviour - just calling home through DNS resolver.
Related to 2025-06-stubsout (using the same remote domain), but without dangerous activity
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2025-06-diar-ai-basic
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
typosquatting
{
"iocs": {
"domains": [
"diar.ai"
]
},
"malicious-packages-origins": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"id": "pypi/2025-06-diar-ai-basic/missing-module",
"sha256": "cc15bd336f5bd3cac178176d652583986c15c4fccbd32e689b5181195535f5f6",
"source": "kam193",
"modified_time": "2025-06-10T20:26:30Z",
"import_time": "2025-12-02T22:30:56.214579355Z"
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"id": "pypi/2025-06-diar-ai-basic/missing-module",
"sha256": "8fbc5749a00c2355e50987775f1b70d9a9dbbe48b531584e5138e2d37578d648",
"source": "kam193",
"modified_time": "2025-06-10T20:26:30Z",
"import_time": "2025-12-02T23:07:19.397956413Z"
},
{
"id": "pypi/2025-06-diar-ai-basic/missing-module",
"sha256": "eb182cc2ee6d5568a2ad3ef2b1a865af4ac9dab662913a3472f6c23ac6998d44",
"source": "kam193",
"versions": [
"0.0.1"
],
"modified_time": "2025-06-10T20:26:30Z",
"import_time": "2025-12-10T21:38:58.521756375Z"
}
]
}