-= Per source details. Do not edit below this line.=-
The package was found to contain malicious code or consuming dependency that contains malicious code
During import, the package starts a reverse shell
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-anthropy
Reasons (based on the campaign):
{
"iocs": {
"domains": [
"dns.subtrace.xyz",
"subtrace.xyz"
],
"ips": [
"54.176.251.240"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-06-anthropy/xforpy",
"import_time": "2026-06-08T19:19:19.201736068Z",
"modified_time": "2026-06-08T18:04:00.431153Z",
"sha256": "6ebd6a0497e01ef631a2c357263bd1af23d88e8d9a9ae46fe39110571949198c",
"source": "kam193",
"versions": [
"0.0.1",
"0.0.2",
"0.0.3",
"0.0.4"
]
},
{
"id": "pypi/2026-06-anthropy/xforpy",
"import_time": "2026-06-08T20:18:23.051789179Z",
"modified_time": "2026-06-08T19:03:14.992418Z",
"sha256": "7765ddca927dca186db905d036f1d6be42cf0f3eb05e58addb9e9cd666a3b9af",
"source": "kam193",
"versions": [
"0.0.1",
"0.0.2",
"0.0.3",
"0.0.4"
]
},
{
"id": "IN-MAL-2026-008575",
"import_time": "2026-07-08T20:32:46.2793782Z",
"modified_time": "2026-07-08T20:30:58Z",
"sha256": "aa4d6837b829b5ed3ef1fcd1f0bf65919df53b2c02c96e7b2c63dbc3e41b965c",
"source": "amazon-inspector",
"versions": [
"0.0.2"
]
},
{
"id": "IN-MAL-2026-008814",
"import_time": "2026-07-08T22:51:23.351088916Z",
"modified_time": "2026-07-08T22:37:01Z",
"sha256": "1725364820b57e26c3e337732eb6611623bb868483cff198744d6a2373807968",
"source": "amazon-inspector",
"versions": [
"0.0.4"
]
},
{
"id": "IN-MAL-2026-008817",
"import_time": "2026-07-08T22:51:23.717188426Z",
"modified_time": "2026-07-08T22:37:28Z",
"sha256": "cfa6cf27e0ff1104ca54ee2482b9a726ef30a562e7e6c51e733299b4848882a6",
"source": "amazon-inspector",
"versions": [
"0.0.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"package_integrity": [
{
"filename": "xforpy-0.0.4-py3-none-any.whl",
"hashes": {
"blake2b_256": "b60a07087b2060fe81315e10e692eda01c4b0e26cfc125f6cac5b8e39dafd1db",
"md5": "f30b536736cb8768e99f64c4d6a70521",
"sha256": "1972f13458ad923d7d46fe7e2af322a35600822ce28779abb4816037c4988546"
}
},
{
"filename": "xforpy-0.0.4.tar.gz",
"hashes": {
"blake2b_256": "71126d78d35e8f405fd047bd543d37e6b022457aa9c7bc2a0a14be11851a1851",
"md5": "c31c773153c9dc4f29940ad1de5ad183",
"sha256": "324a2a4a85047123d77d4f4119e4f131b5855fcd952a839da7a589985e94c34d"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/xforpy/MAL-2026-5332.json"