Supply-chain threat intelligence
Risk score
92
Indexed incident for sf-silly-goose-requests (pypi).
Package uses trufflehog to detect secrets and exfiltrates them to a hardcoded location
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-sf-silly-goose-requests
Reasons (based on the campaign):
exfiltration-credentials
exfiltration-env-variables
Indicators
Timeline