-= Per source details. Do not edit below this line.=-
During installation, the package attempts to exfiltrate cloud tokens
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-05-veriftest1asdl
Reasons (based on the campaign):
exfiltration-cloud-tokens
The package overrides the install command in setup.py to execute malicious code during installation.
The OpenSSF Package Analysis project identified 'testveriftest1asdlaaaa' @ 1 (pypi) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"modified_time": "2025-05-06T10:06:30Z",
"versions": [
"1"
],
"sha256": "f038353a795c169c81650e7566b947bfddc4dcf48ad65eba74173d228bae2939",
"source": "ossf-package-analysis",
"import_time": "2025-05-06T10:06:34.706941544Z"
},
{
"modified_time": "2025-05-06T10:01:15Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "b4e69cdec1c0ace2105b57e6f6e8c778fc8a00a2a645a89072974be3f867678e",
"id": "pypi/2025-05-veriftest1asdl/testveriftest1asdlaaaa",
"source": "kam193",
"import_time": "2025-12-02T22:30:55.638457129Z"
},
{
"modified_time": "2025-05-06T10:01:15Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "3b241cae62c005e3cd31a8251941ab101ebcca75aa4c8cb988905e87529339cd",
"id": "pypi/2025-05-veriftest1asdl/testveriftest1asdlaaaa",
"source": "kam193",
"import_time": "2025-12-02T23:07:18.679539161Z"
},
{
"modified_time": "2025-05-06T10:01:15Z",
"versions": [
"1"
],
"sha256": "b7ff08b99f2d0dc85260eb0189fd79c36cd609850bb09ae0691abd2e757bd6c5",
"id": "pypi/2025-05-veriftest1asdl/testveriftest1asdlaaaa",
"source": "kam193",
"import_time": "2025-12-10T21:38:57.865876497Z"
}
],
"iocs": {
"urls": [
"https://webhook.site/bed8144a-900b-498a-a451-1b14dc19fb39"
]
}
}