-= Per source details. Do not edit below this line.=-
Package exploits dependency confusion. A beacon request is used to report usage back, but no additional information are exfiltrated.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-beacon-dependency-confusion
Reasons (based on the campaign):
typosquatting
dependency-confusion
{
"malicious-packages-origins": [
{
"sha256": "c6e91ab35953cced9cf886a16976bb282de1dcf804938f4179a2dcf8dc1af731",
"source": "kam193",
"modified_time": "2026-02-01T21:00:48.571244Z",
"id": "pypi/GENERIC-beacon-dependency-confusion/hultine",
"versions": [
"1.0.1",
"2.0.0",
"2.0.1",
"2.0.2",
"2.0.3",
"2.0.4"
],
"import_time": "2026-02-01T21:09:06.977077082Z"
}
]
}