-= Per source details. Do not edit below this line.=-
Importing the package starts a script that takes commands from remote server and executes locally
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-03-python-socket-test
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"id": "RLMA-2025-02524",
"import_time": "2025-04-25T09:36:47.589754624Z",
"modified_time": "2025-04-23T16:06:35Z",
"sha256": "382f73d1e1afdcb53f0f53d1971a55c246aeab8a4b44cb4bd2e8ad450aac24e4",
"source": "reversing-labs",
"versions": [
"1.0.0",
"1.0.1",
"1.1.1",
"2.0.0",
"2.0.1"
]
},
{
"id": "pypi/2025-03-python-socket-test/python-socket-test",
"import_time": "2025-12-02T22:30:55.493825504Z",
"modified_time": "2025-03-18T10:22:52Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "ebda3713b5dc5450e5ab29810baa209491367514409022f5514a592dd2aa43b3",
"source": "kam193"
},
{
"id": "pypi/2025-03-python-socket-test/python-socket-test",
"import_time": "2025-12-02T23:07:18.518739202Z",
"modified_time": "2025-03-18T10:22:52Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "93a8d30e631680bace9b05db1ac189cbcc472895fcfb1db40f4df52f301a6599",
"source": "kam193"
},
{
"id": "pypi/2025-03-python-socket-test/python-socket-test",
"import_time": "2025-12-10T21:38:57.737805993Z",
"modified_time": "2025-03-18T10:22:52Z",
"sha256": "84b55a44b9131e861d0ebe1884bed3f6ec52a705ccb96b8a3861e1a50a1fb8d0",
"source": "kam193",
"versions": [
"1.0.0",
"1.0.1",
"1.1.1",
"2.0.0",
"2.0.1"
]
},
{
"id": "RLUA-2026-00668",
"import_time": "2026-03-19T12:20:18.807021936Z",
"modified_time": "2026-03-18T12:17:49Z",
"sha256": "503a73cf105cfe27c48a3bbfce49f33a4ec01fa39ff27d6ebeeebbbd6f3526ba",
"source": "reversing-labs"
}
]
}