-= Per source details. Do not edit below this line.=-
Installing packages exfiltrates data (different in different packages and versions) or run revshells
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-08-learning-pypi-demo-nisimi
Reasons (based on the campaign):
The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
exfiltration-generic
{
"malicious-packages-origins": [
{
"import_time": "2025-09-26T11:05:32.002794365Z",
"sha256": "a210911a587ceac39ace6765e9782ff6f25bfc1b1a19b3c346d94d7fb0efb492",
"source": "reversing-labs",
"versions": [
"0.1.8"
],
"id": "RLMA-2025-04756",
"modified_time": "2025-09-26T09:13:52Z"
},
{
"import_time": "2025-12-02T22:30:55.088660857Z",
"sha256": "8bb67ea582f7a4d2d52411f11cc262ea997284dc51573bdac63afcc202e9edda",
"source": "kam193",
"versions": [
"0.1.8"
],
"id": "pypi/2025-08-learning-pypi-demo-nisimi/data-processing-utils",
"modified_time": "2025-09-03T16:45:23.122294Z"
},
{
"import_time": "2025-12-02T23:07:18.101642225Z",
"sha256": "f5c7542831f6f9fe72a65e436b1f85c10261aac12ceae6f1bcc490afad6d1aaa",
"source": "kam193",
"versions": [
"0.1.8"
],
"id": "pypi/2025-08-learning-pypi-demo-nisimi/data-processing-utils",
"modified_time": "2025-09-03T16:45:23.122294Z"
},
{
"import_time": "2026-03-19T12:19:38.198081447Z",
"sha256": "5d0b15747163278ec7c46fa1de9916fa6b2a23e3e2adcee9eb22965001e6a629",
"source": "reversing-labs",
"id": "RLUA-2026-00247",
"modified_time": "2026-03-18T12:13:03Z"
}
],
"iocs": {
"domains": [
"evduuu5l01di1hdn9i5qslhxzo5ft6ju8.oastify.com",
"xz0dyd944kh150h6d199w4lg379yx0lp.oastify.com",
"v95b8bj2eirzfyr4nzj762ved5jw71vq.oastify.com"
]
}
}