-= Per source details. Do not edit below this line.=-
During installation, if run under a specific username, the package downloads and installs two executables identified as backdoors trojans.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-03-thisismytest123
Reasons (based on the campaign):
Downloads and executes a remote executable.
backdoor
malware
The OpenSSF Package Analysis project identified 'thisismytest123' @ 1.0.0 (pypi) as malicious.
It is considered malicious because:
{
"iocs": {
"urls": [
"http://8.217.174.149:8888/supershell/compile/download/java",
"https://shim.oss-cn-hongkong.aliyuncs.com/shim",
"https://shim.oss-cn-hongkong.aliyuncs.com/shim.conf"
]
},
"malicious-packages-origins": [
{
"import_time": "2026-03-27T09:22:29.114673103Z",
"modified_time": "2026-03-27T07:47:07Z",
"source": "ossf-package-analysis",
"sha256": "7587966a3d79cfe783b06cfea4893cd3d3c445d8c1783c81d4b1ff797e591141",
"versions": [
"1.0.0"
]
},
{
"import_time": "2026-03-27T09:22:29.24318088Z",
"modified_time": "2026-03-27T08:14:18Z",
"source": "ossf-package-analysis",
"sha256": "c1564ec3a6b1a2fee0aacfbeafde84cba8e249a9294b771f43610ff371942a6d",
"versions": [
"2.0.0"
]
},
{
"import_time": "2026-03-27T14:25:43.463936915Z",
"modified_time": "2026-03-27T13:55:03.756631Z",
"id": "pypi/2026-03-thisismytest123/thisismytest123",
"source": "kam193",
"sha256": "7640ee5ded7bcafbd9863565d68a7768bdc9bd2abca56a69d73576e7e9b2c0df",
"versions": [
"1.0.0",
"2.0.0"
]
}
]
}