-= Per source details. Do not edit below this line.=-
Setup.py contains a reverse shell
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-02-mirage-rce
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"id": "RLMA-2025-01973",
"import_time": "2025-03-31T07:07:05.898320121Z",
"sha256": "9a8ec5d1258e90f9dbbf90175f3e40ef38ca58cae2b5b2e048bd34045e25044b",
"modified_time": "2025-03-28T13:05:51Z",
"source": "reversing-labs",
"versions": [
"0.0.1"
]
},
{
"id": "pypi/2025-02-mirage-rce/mirage-rce",
"import_time": "2025-12-02T22:30:55.339089797Z",
"sha256": "9335196ccce03f70d20f319760081a6a4d5549bfbe6a733be38084890bbc03f6",
"modified_time": "2025-03-02T17:30:26Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"source": "kam193"
},
{
"id": "pypi/2025-02-mirage-rce/mirage-rce",
"import_time": "2025-12-02T23:07:18.368465937Z",
"sha256": "f9ba7e438828f3bcacd252bc54f00732b129fe6fc8f6a9909d964720ac1e6420",
"modified_time": "2025-03-02T17:30:26Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"source": "kam193"
},
{
"id": "pypi/2025-02-mirage-rce/mirage-rce",
"import_time": "2025-12-10T21:38:57.594480493Z",
"sha256": "28fad7d114fd99e403c318ae35e13024582b3211e1a5e050814d389bdd1236be",
"modified_time": "2025-03-02T17:30:26Z",
"source": "kam193",
"versions": [
"0.0.1"
]
},
{
"id": "RLUA-2026-00523",
"import_time": "2026-03-19T12:20:04.808254811Z",
"sha256": "af0bafdf3a203e82a1bf325412ab1cd59785ab0c7928eb73294b3246974a82cf",
"modified_time": "2026-03-18T12:16:07Z",
"source": "reversing-labs"
}
]
}