-= Per source details. Do not edit below this line.=-
launchdarkly-ai-server-sdk 1.0.1 (pypi) was scanned across 7 files with no a static rule matches and no traced behavior of concern. No install-time or import-time network I/O, credential access, subprocess execution, or persistence mechanisms were observed.
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-standard-pypi-install-pentest
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
The package overrides the install command in setup.py to execute malicious code during installation.
{
"malicious-packages-origins": [
{
"source": "kam193",
"import_time": "2026-08-04T10:26:58.244275836Z",
"sha256": "7d6642383cc89e975e740067b88a401953adee9187b37a14a33acc833b32d727",
"modified_time": "2026-08-04T10:10:35.394711Z",
"id": "pypi/GENERIC-standard-pypi-install-pentest/launchdarkly-ai-server-sdk",
"versions": [
"1.0.1",
"1.9.9"
]
},
{
"source": "amazon-inspector",
"import_time": "2026-08-05T07:06:41.938588209Z",
"sha256": "460d36c416400537f8c90171c7821b191e0af69df3ec9f0c906300f50b0ea93f",
"modified_time": "2026-08-05T06:08:17Z",
"id": "IN-MAL-2026-013334",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"filename": "launchdarkly_ai_server_sdk-1.0.1-py3-none-any.whl",
"hashes": {
"md5": "e6cfe621111175cbe63bb38783a0b346",
"blake2b_256": "295f1ed75398401e3e7550b5edace8ead1eea34e58169e134a02ee8440231743",
"sha256": "9832e3ffb9515d97ab7a3bee343bd31a15ace5c221110994bbaff4f84e87af13"
}
},
{
"filename": "launchdarkly_ai_server_sdk-1.0.1.tar.gz",
"hashes": {
"md5": "6610ab4d2260cb16b99fa1575219f881",
"blake2b_256": "1a499bddd24f005b3c2828dc112add4526d199761ea82beeb8391334a29069e9",
"sha256": "81772ad03902185c2c3e7b97d00869d95bf25e617b47c4a1eb5c82e3d27a6e0a"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/launchdarkly-ai-server-sdk/MAL-2026-11519.json"