Supply-chain threat intelligence
Risk score
92
Indexed incident for lib-1779997093-yjeeqn (pypi).
During installation, the package opens a reverse shell
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-my-test-package-2025-xyz
Reasons (based on the campaign):
The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
The package overrides the install command in setup.py to execute malicious code during installation.
Indicators
Timeline