-= Per source details. Do not edit below this line.=-
The package appears to be a typosquatting research attempt. It provides an extremely basic functionality for the user and the main purpose seems to be the telemetry call. Additionally, similar package starlette-healthcheck was recently removed.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-starlette-healthcheck
Reasons (based on the campaign):
action-hidden-in-lib-usage
typosquatting
{
"iocs": {
"domains": [
"ca-fusion-dev-collector.victorioussmoke-2f009910.uksouth.azurecontainerapps.io"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-09-starlette-healthcheck/starlette-healthchecks",
"import_time": "2026-09-21T17:38:33.982933083Z",
"modified_time": "2026-09-21T16:50:02.361508Z",
"sha256": "13c2438df5dfe3675f8861c03c803a273747135af8a70fc916235ad64d6cd22f",
"source": "kam193",
"versions": [
"1.3.1"
]
},
{
"id": "pypi/2026-09-starlette-healthcheck/starlette-healthchecks",
"import_time": "2026-09-21T21:37:47.148069691Z",
"modified_time": "2026-09-21T21:05:51.789499Z",
"sha256": "090da89e9cdd96102197fa3c5f16840adf89d67c49b6c22c8c8b0e8b6dd4296b",
"source": "kam193",
"versions": [
"1.3.1",
"1.3.2"
]
}
]
}