-= Per source details. Do not edit below this line.=-
During installation or importing the module, the package starts a reverse shell to hardcoded locatiom
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-12-aiogram-sever-patch
Reasons (based on the campaign):
The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
The package overrides the install command in setup.py to execute malicious code during installation.
dependency-confusion
{
"malicious-packages-origins": [
{
"source": "kam193",
"sha256": "0be41c08090971a10e54930628353748c82ed55c0f9795b26a932f806852fd4f",
"import_time": "2025-12-25T15:07:34.090338025Z",
"id": "pypi/2025-12-aiogram-sever-patch/aiogram-sever-patch",
"versions": [
"3.3.8",
"3.3.7",
"3.3.9"
],
"modified_time": "2025-12-25T14:47:00.746403Z"
},
{
"source": "kam193",
"sha256": "b023a030405c79b4e6de1792f36c9b141be617f58207f4457b9387ff71eeaf69",
"import_time": "2025-12-25T16:08:11.040317764Z",
"id": "pypi/2025-12-aiogram-sever-patch/aiogram-sever-patch",
"versions": [
"3.3.8",
"3.3.7",
"3.3.9",
"3.5.0"
],
"modified_time": "2025-12-25T15:14:07.246518Z"
},
{
"source": "kam193",
"sha256": "08eb3f7596c1a64bfa8b9cb506c57580a1b04447fff55fe5f235131149743637",
"import_time": "2025-12-25T17:06:39.885578167Z",
"id": "pypi/2025-12-aiogram-sever-patch/aiogram-sever-patch",
"versions": [
"3.3.8",
"3.3.7",
"3.3.9",
"3.5.0",
"3.6.0"
],
"modified_time": "2025-12-25T15:55:13.929407Z"
}
],
"iocs": {
"ips": [
"147.45.124.42"
]
}
}