-= Per source details. Do not edit below this line.=-
During installation, the package exfiltrates env variables and data from different process memory to a remote location
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-01-do-not-install-this-package-002
Reasons (based on the campaign):
exfiltration-generic
exfiltration-credentials
exfiltration-env-variables
The package overrides the install command in setup.py to execute malicious code during installation.
{
"iocs": {
"domains": [
"bachelor-thesis-001.proxy.beeceptor.com",
"open-hookbin.vercel.app"
],
"urls": [
"https://bachelor-thesis-001.free.beeceptor.com"
]
},
"malicious-packages-origins": [
{
"source": "kam193",
"id": "pypi/2026-01-do-not-install-this-package-002/do-not-install-this-package-004",
"modified_time": "2026-03-15T17:05:57.058935Z",
"sha256": "155862095ddb7d3410298aef76abdda3e7eeaf5609b72f97c30790c317b8d1cb",
"versions": [
"0.1.0"
],
"import_time": "2026-03-15T17:44:00.761027461Z"
}
]
}