-= Per source details. Do not edit below this line.=-
Package silently executes remote code during import.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-lognest
Reasons (based on the campaign):
{
"iocs": {
"domains": [
"pypkg.dev"
],
"urls": [
"https://pypkg.dev/project/logger/json"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-05-lognest/pylogft",
"sha256": "ca79d0eb10bc090eadb383ded3d5c47143d4d0e9eaa206840d3d803fcfc4be9a",
"modified_time": "2026-05-22T06:52:38.062189Z",
"versions": [
"0.1.0",
"0.1.1"
],
"import_time": "2026-05-22T07:48:05.85203417Z",
"source": "kam193"
}
]
}