-= Per source details. Do not edit below this line.=-
Dependency confusion demonstration package with reporting through a decorator function
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2025-12-sec-lab-it
Reasons (based on the campaign):
dependency-confusion
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
typosquatting
{
"iocs": {
"domains": [
"dependency-confusion.sec-lab.it",
"b32.simplest-solutions.pl",
"simplest-solutions.pl",
"sec-lab.it"
]
},
"malicious-packages-origins": [
{
"source": "kam193",
"modified_time": "2026-01-06T19:10:44.172813Z",
"sha256": "993085ca23a6a729d332eade4d58778a42c1d19b18237ab4b3c3a6bacf9fd126",
"import_time": "2026-01-06T20:08:10.793233643Z",
"versions": [
"0.1.0",
"0.2.0"
],
"id": "pypi/2025-12-sec-lab-it/py-publish-test-0126"
}
]
}