-= Per source details. Do not edit below this line.=-
During installation, the package exfiltrates env variables and data from different process memory to a remote location
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-01-do-not-install-this-package-002
Reasons (based on the campaign):
exfiltration-generic
exfiltration-credentials
exfiltration-env-variables
The package overrides the install command in setup.py to execute malicious code during installation.
{
"iocs": {
"urls": [
"https://bachelor-thesis-001.free.beeceptor.com"
],
"domains": [
"bachelor-thesis-001.proxy.beeceptor.com"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-01-do-not-install-this-package-002/do-not-install-this-package-003",
"import_time": "2026-02-24T15:50:45.91387336Z",
"sha256": "3b7a8f2037bd4c28a5474af17179da0c12e37019623f5efa4d081d60758d4ac9",
"source": "kam193",
"modified_time": "2026-02-24T15:18:17.776656Z",
"versions": [
"0.1.0"
]
},
{
"id": "pypi/2026-01-do-not-install-this-package-002/do-not-install-this-package-003",
"import_time": "2026-03-15T17:44:00.760237725Z",
"sha256": "cd709903397a17cff31bf9a05a6fc297dc83c2b440bb18c24f442ff931aad2df",
"source": "kam193",
"modified_time": "2026-02-24T15:18:17.776656Z",
"versions": [
"0.1.0"
]
}
]
}