-= Per source details. Do not edit below this line.=-
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-standard-pypi-install-pentest
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
The package overrides the install command in setup.py to execute malicious code during installation.
{
"malicious-packages-origins": [
{
"id": "pypi/GENERIC-standard-pypi-install-pentest/dlmm",
"import_time": "2026-08-11T05:54:24.92490557Z",
"sha256": "044faa804b628c1751f6fa5f66a5f8835ecda1f4d2837ae70411d4630a0607ad",
"versions": [
"1.0.0"
],
"source": "kam193",
"modified_time": "2026-08-11T05:42:22.988066Z"
},
{
"id": "pypi/2026-08-dlmm/dlmm",
"import_time": "2026-08-11T06:52:08.588791761Z",
"sha256": "8fba47981ede7481948d0e01c8f31bf1c089d1ceb867c091674a6723f997c620",
"modified_time": "2026-08-11T06:21:29.466082Z",
"source": "kam193",
"versions": [
"1.0.0"
]
},
{
"id": "pypi/2026-08-dlmm/dlmm",
"import_time": "2026-08-11T11:20:20.171616595Z",
"sha256": "ee359b60207a173d75479e7e6c585187b8b72eeb445a3613e64457dd5a19b8c1",
"versions": [
"1.0.0"
],
"source": "kam193",
"modified_time": "2026-08-11T06:21:29.466082Z"
}
],
"iocs": {
"urls": [
"https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09"
]
}
}