-= Per source details. Do not edit below this line.=-
Generic campaign for all (likely) research / pentests, where the amount or art of collected data raises questions about the privacy, security and ethical side.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: GENERIC-questionable-pentest
Reasons (based on the campaign):
exfiltration-env-variables
exfiltration-generic
The package overrides the install command in setup.py to execute malicious code during installation.
typosquatting
{
"malicious-packages-origins": [
{
"id": "RLMA-2024-08523",
"modified_time": "2024-10-16T14:43:46Z",
"source": "reversing-labs",
"sha256": "b9afd964611a469cd6fe62f9684544eb34337fedd29bc97df5110e0f7829fd2b",
"versions": [
"99.99.99",
"99.99.100",
"99.99.101",
"99.99.102",
"99.99.103",
"99.99.105"
],
"import_time": "2024-10-24T00:57:00.745636075Z"
},
{
"id": "pypi/GENERIC-questionable-pentest/mlc-llm-nightly",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2024-09-06T11:29:16Z",
"source": "kam193",
"sha256": "f82afa0378a3a21d3f12574493e94e921aec9113684cc1654a533ce1f7aa716f",
"import_time": "2025-12-02T22:30:55.343157429Z"
},
{
"id": "pypi/GENERIC-questionable-pentest/mlc-llm-nightly",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2024-09-06T11:29:16Z",
"source": "kam193",
"sha256": "bdf6d47b319cb60e32a6f2942beaa54bfe6ccc01bb72a8337f062746d49ace38",
"import_time": "2025-12-02T23:07:18.372838297Z"
},
{
"id": "pypi/GENERIC-questionable-pentest/mlc-llm-nightly",
"modified_time": "2024-09-06T11:29:16Z",
"source": "kam193",
"sha256": "0bb339dee4aefeb8ea2f6f6f6e92413a44fd5f90aeb7d585dd022dc80842ac7b",
"versions": [
"99.99.99",
"99.99.100",
"99.99.101",
"99.99.102",
"99.99.103",
"99.99.105"
],
"import_time": "2025-12-10T21:38:57.598645916Z"
}
]
}