-= Per source details. Do not edit below this line.=-
During installation, the package exfiltrates cloud tokens from the environment.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-redteam-qxz7-utils
Reasons (based on the campaign):
exfiltration-cloud-tokens
The package overrides the install command in setup.py to execute malicious code during installation.
{
"malicious-packages-origins": [
{
"modified_time": "2026-06-01T13:04:52.49417Z",
"versions": [
"1.0.0"
],
"sha256": "855b67c0cf1aaed6f5e0ce3a67478a20cd4244c56424002feeeb0dea1a875848",
"id": "pypi/2026-06-redteam-qxz7-utils/redteam-qxz7-utils",
"source": "kam193",
"import_time": "2026-06-01T14:33:25.04095477Z"
}
],
"iocs": {
"domains": [
"disrupt-evasive-sterility.ngrok-free.dev"
],
"urls": [
"https://disrupt-evasive-sterility.ngrok-free.dev/creds"
]
}
}