Supply-chain threat intelligence

Incident detail

criticalpypi·typosquatting·github

Malicious code in youreallydontwantthispackage2132 (PyPI)

youreallydontwantthispackage2132

Risk score

92

AI summary

Indexed incident for youreallydontwantthispackage2132 (pypi).

Description

Generic campaign for all (likely) research / pentests, where the amount or art of collected data raises questions about the privacy, security and ethical side.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: GENERIC-questionable-pentest

Reasons (based on the campaign):

  • exfiltration-env-variables

  • exfiltration-generic

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • typosquatting

The OpenSSF Package Analysis project identified 'youreallydontwantthispackage2132' @ 1.0.3 (pypi) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents