-= Per source details. Do not edit below this line.=-
During installation, the package attempts to exfiltrate cloud tokens
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-05-veriftest1asdl
Reasons (based on the campaign):
exfiltration-cloud-tokens
The package overrides the install command in setup.py to execute malicious code during installation.
{
"iocs": {
"urls": [
"https://webhook.site/bed8144a-900b-498a-a451-1b14dc19fb39"
]
},
"malicious-packages-origins": [
{
"source": "reversing-labs",
"id": "RLMA-2025-02611",
"modified_time": "2025-05-22T12:33:53Z",
"sha256": "bd37166c95b260a650c6fb2c96e2da5eae8b7cda8ccb7384b506d4a1c39ade68",
"versions": [
"1"
],
"import_time": "2025-05-22T14:06:38.858052106Z"
},
{
"source": "kam193",
"id": "pypi/2025-05-veriftest1asdl/veriftest1asdlaaa",
"modified_time": "2025-05-06T10:01:15Z",
"sha256": "8953c802be029ee2cf0c07fc075ee62ad7b6170eabf4996f4e78266a089b8c07",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.711922719Z"
},
{
"source": "kam193",
"id": "pypi/2025-05-veriftest1asdl/veriftest1asdlaaa",
"modified_time": "2025-05-06T10:01:15Z",
"sha256": "8ca63296b7d7f9b656944bcaf65cc918b709a2071d1ea5f16d1a7422a9df931e",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.751194504Z"
},
{
"source": "kam193",
"id": "pypi/2025-05-veriftest1asdl/veriftest1asdlaaa",
"modified_time": "2025-05-06T10:01:15Z",
"sha256": "0b1c39a6af7a9b591a2624cef50f3984f09f5144225dbb34a6c626a376c7af1b",
"versions": [
"1"
],
"import_time": "2025-12-10T21:38:57.923089895Z"
},
{
"source": "reversing-labs",
"id": "RLUA-2026-00888",
"modified_time": "2026-03-18T12:20:09Z",
"sha256": "1e28765b13dc5a1d0474caac0adc41e2a80f1facea8cda1cc7ad8ac1173b5dba",
"import_time": "2026-03-19T12:20:40.375690452Z"
}
]
}