-= Per source details. Do not edit below this line.=-
During installation, multiple sensitive environment variables are being exfiltrated.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-apexomni-client
Reasons (based on the campaign):
exfiltration-env-variables
dependency-confusion
exfiltration-credentials
The package overrides the install command in setup.py to execute malicious code during installation.
{
"malicious-packages-origins": [
{
"id": "pypi/2026-05-apexomni-client/apexomni-client",
"import_time": "2026-05-02T11:20:00.625149304Z",
"sha256": "497dca02206d8084e5a7e135245489a5ef9dd03f318b138574bc43386ddac0ef",
"versions": [
"99.99.99"
],
"modified_time": "2026-05-02T10:31:16.109025Z",
"source": "kam193"
}
]
}