Supply-chain threat intelligence
Risk score
92
Indexed incident for youreallydontwantthispackage2132 (pypi).
Generic campaign for all (likely) research / pentests, where the amount or art of collected data raises questions about the privacy, security and ethical side.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: GENERIC-questionable-pentest
Reasons (based on the campaign):
exfiltration-env-variables
exfiltration-generic
The package overrides the install command in setup.py to execute malicious code during installation.
typosquatting
The OpenSSF Package Analysis project identified 'youreallydontwantthispackage2132' @ 1.0.3 (pypi) as malicious.
It is considered malicious because:
Indicators
Timeline