-= Per source details. Do not edit below this line.=-
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-standard-pypi-install-pentest
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
The package overrides the install command in setup.py to execute malicious code during installation.
{
"malicious-packages-origins": [
{
"id": "pypi/GENERIC-standard-pypi-install-pentest/morpho-sdk",
"import_time": "2026-08-11T10:23:21.697372101Z",
"sha256": "cb58dff63faa08e128ddd0d8d38b82c0711bb60d09d19755a8e8f398fa7d511d",
"modified_time": "2026-08-11T09:48:42.070386Z",
"source": "kam193",
"versions": [
"1.0.0"
]
},
{
"id": "pypi/2026-08-dlmm/morpho-sdk",
"import_time": "2026-08-11T11:20:20.173322708Z",
"sha256": "c7a717848fd32ff9a8aa50237f04d0538ade50873a7e5eb3ed7be01176747775",
"versions": [
"1.0.0"
],
"source": "kam193",
"modified_time": "2026-08-11T10:59:38.82415Z"
},
{
"id": "pypi/2026-08-dlmm/morpho-sdk",
"import_time": "2026-08-12T08:36:26.16384491Z",
"sha256": "573be3b67dc44476de46ed72c0810a627e3162e003b5331f12b971374c98da0c",
"versions": [
"1.0.0"
],
"source": "kam193",
"modified_time": "2026-08-11T10:59:38.82415Z"
}
],
"iocs": {
"urls": [
"https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09"
]
}
}