-= Per source details. Do not edit below this line.=-
During installation, the code exfiltrates basic information and exfiltrates more information to a localhost service as well as starts a reverse shell there. It seems to be an internal test that was uploaded to a public repository.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2026-08-joule-btp-extension
Reasons (based on the campaign):
The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
{
"iocs": {
"urls": [
"https://42b1-2a02-2ad0-103-2841-51cc-a5b3-6bc2-68fe.ngrok-free.app/asd"
]
},
"malicious-packages-origins": [
{
"source": "kam193",
"modified_time": "2026-08-11T19:38:53.616439Z",
"sha256": "c460336aaf7e02cc7b37e4a0e58df5e22431f9de9ea852af21bb1aa2f333039c",
"id": "pypi/2026-08-joule-btp-extension/joule-sbx-poc",
"versions": [
"0.1.0"
],
"import_time": "2026-08-11T19:53:29.929172486Z"
}
]
}