-= Per source details. Do not edit below this line.=-
Generic campaign for all (likely) research / pentests, where the amount or art of collected data raises questions about the privacy, security and ethical side.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: GENERIC-questionable-pentest
Reasons (based on the campaign):
exfiltration-env-variables
exfiltration-generic
The package overrides the install command in setup.py to execute malicious code during installation.
typosquatting
{
"malicious-packages-origins": [
{
"id": "pypi/GENERIC-questionable-pentest/vllm-plugins",
"sha256": "4fa0706d497278a502d158c89d51645a6f4e8187ca325aacaa59facccf542a03",
"source": "kam193",
"versions": [
"99.99.99"
],
"modified_time": "2026-02-10T19:19:17.108017Z",
"import_time": "2026-02-10T19:54:11.777636522Z"
}
]
}