-= Per source details. Do not edit below this line.=-
Installing the package starts a revshell and download and starts a remote script (depending on version, different malicious functionality). The name seems to imitate CPAN.org
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-06-cpan
Reasons (based on the campaign):
The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
impersonation
Downloads and executes a remote malicious script.
{
"malicious-packages-origins": [
{
"modified_time": "2025-07-31T19:14:43Z",
"versions": [
"0.0.2",
"0.0.3"
],
"sha256": "bd1681dc89631934bce508a308d2c708603f6d09ca9cb6efbe90f4b33d1cbaea",
"id": "RLMA-2025-03574",
"source": "reversing-labs",
"import_time": "2025-08-01T10:07:10.52261363Z"
},
{
"modified_time": "2025-06-28T09:28:42Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "7d1167d235aa8d1bfa384247116621d8a00d34455aabf31bc8f46e5f348ae7b2",
"id": "pypi/2025-06-cpan/cpan",
"source": "kam193",
"import_time": "2025-12-02T22:30:55.072464118Z"
},
{
"modified_time": "2025-06-28T09:28:42Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "e70433969aea3c8283f99098b25b8a598f427b5fd451e9bfd5bc46098704bfb2",
"id": "pypi/2025-06-cpan/cpan",
"source": "kam193",
"import_time": "2025-12-02T23:07:18.082630638Z"
},
{
"modified_time": "2025-06-28T09:28:42Z",
"versions": [
"0.0.1",
"0.0.2",
"0.0.3"
],
"sha256": "58814925612b24ead324b54f764c54aea2512fe1a85e1ba3fd152395a2acaa93",
"id": "pypi/2025-06-cpan/cpan",
"source": "kam193",
"import_time": "2025-12-10T21:38:57.374165892Z"
},
{
"modified_time": "2026-03-18T12:12:51Z",
"versions": [
"0.0.1"
],
"sha256": "4b423c9367571c3f7f63f1df132ff76424ff0cebb455a95d212c659dac56bbb8",
"id": "RLUA-2026-00226",
"source": "reversing-labs",
"import_time": "2026-03-19T12:19:36.34520604Z"
}
],
"iocs": {
"urls": [
"http://124.221.175.251/11.sh",
"http://124.221.175.251/start.sh"
],
"ips": [
"124.221.175.251"
]
}
}