-= Per source details. Do not edit below this line.=-
During installation, the package attempts to exfiltrate cloud tokens
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-05-veriftest1asdl
Reasons (based on the campaign):
exfiltration-cloud-tokens
The package overrides the install command in setup.py to execute malicious code during installation.
{
"iocs": {
"urls": [
"https://webhook.site/bed8144a-900b-498a-a451-1b14dc19fb39"
]
},
"malicious-packages-origins": [
{
"id": "RLMA-2025-02612",
"import_time": "2025-05-22T14:06:38.956752512Z",
"sha256": "14006d51a1c0401267f0cde60e05a37e4f73cdccc8d411beab2a87334f248dab",
"source": "reversing-labs",
"modified_time": "2025-05-22T12:33:53Z",
"versions": [
"1"
]
},
{
"id": "pypi/2025-05-veriftest1asdl/veriftest1asdlaaaa",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.712866132Z",
"sha256": "b92f906eae88df2f6c2e96a57b2d258e815305abe81fab70fecee74b819da73c",
"source": "kam193",
"modified_time": "2025-05-06T10:01:15Z"
},
{
"id": "pypi/2025-05-veriftest1asdl/veriftest1asdlaaaa",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.752072524Z",
"sha256": "18d30d48c72a61cda2e8b0ecd3a27b958e8964b4c65833cb780186382285101d",
"source": "kam193",
"modified_time": "2025-05-06T10:01:15Z"
},
{
"id": "pypi/2025-05-veriftest1asdl/veriftest1asdlaaaa",
"import_time": "2025-12-10T21:38:57.923889565Z",
"sha256": "a213b19e8ffaf71235072fe1ae7f0282ee5c8ca457aa873ccb31d5955b314b26",
"source": "kam193",
"modified_time": "2025-05-06T10:01:15Z",
"versions": [
"1"
]
},
{
"id": "RLUA-2026-00889",
"import_time": "2026-03-19T12:20:40.473058197Z",
"sha256": "f19843d6dc712a5df94bd61a64df361987d7919eb999f05800c3f1947107a368",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:20:10Z"
}
]
}