-= Per source details. Do not edit below this line.=-
Packages that seem to be created by a legit bug bounty hunter. Designed to look like created by different organisations, they contain a couple of data exfiltration (including all env variables) and potential remote code execution (though the URL seems not to serve any code).
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-05-sl4x01
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
exfiltration-env-variables
impersonation
The OpenSSF Package Analysis project identified 'dial-xl' @ 0.0.1 (pypi) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "0febe63d78b1149e91af60c89ae73e492d43cb35f04dc6aaee2c4048987081a9",
"modified_time": "2025-05-10T13:41:29Z",
"source": "ossf-package-analysis",
"versions": [
"0.0.1"
],
"import_time": "2025-05-12T00:25:55.382499014Z"
},
{
"id": "RLMA-2025-02567",
"sha256": "981cfe7e3f073f4617d3753692488e7d648638062ce86107e80053f7e42b27bf",
"modified_time": "2025-05-22T12:33:30Z",
"source": "reversing-labs",
"versions": [
"0.0.1"
],
"import_time": "2025-05-22T14:06:35.135348536Z"
},
{
"id": "pypi/2025-05-sl4x01/dial-xl",
"sha256": "bbee7f1a70bb8bd38a215ed7b6ed02042387824942682e3caedcd4dbe255ac29",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"modified_time": "2025-05-10T17:59:53Z",
"source": "kam193",
"import_time": "2025-12-02T22:30:55.099069131Z"
},
{
"id": "pypi/2025-05-sl4x01/dial-xl",
"sha256": "129b71dc44955e560cd56ff53e0be19aced751699016fa96cb04ee75d2e76e3b",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"modified_time": "2025-05-10T17:59:53Z",
"source": "kam193",
"import_time": "2025-12-02T23:07:18.110205419Z"
},
{
"id": "pypi/2025-05-sl4x01/dial-xl",
"sha256": "6998be6df530663dae02f1db20706272aefdaa812605fb740493e5f41d63c126",
"modified_time": "2025-05-10T17:59:53Z",
"source": "kam193",
"versions": [
"0.0.1"
],
"import_time": "2025-12-10T21:38:57.39546625Z"
}
],
"iocs": {
"domains": [
"sl4x0.xyz"
]
}
}