-= Per source details. Do not edit below this line.=-
During installation, the package attempts to exfiltrate specific sensitive environment variables.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-02-genvia-utils
Reasons (based on the campaign):
exfiltration-env-variables
The package overrides the install command in setup.py to execute malicious code during installation.
dependency-confusion
{
"malicious-packages-origins": [
{
"sha256": "daedaaf2f945a1cc86a93f479d8284153533d387ddd7b00418991a7998a37e11",
"id": "pypi/2026-02-genvia-utils/genvia-utils",
"source": "kam193",
"modified_time": "2026-02-01T19:06:58.378839Z",
"import_time": "2026-02-01T19:39:49.022041756Z",
"versions": [
"6.0.2",
"99.99.99"
]
}
]
}