Supply-chain threat intelligence
Risk score
92
Indexed incident for youreallydontwantthispackage2131 (pypi).
Installing the package attempts to exfiltrate GCP tokens. As it uses a random names and/or targets specific accounts, it's most probably a (pen)test.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2024-10-gal32fjdsbf89hnd-gcp-token
Reasons (based on the campaign):
The OpenSSF Package Analysis project identified 'youreallydontwantthispackage2131' @ 1.0.1 (pypi) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
Indicators
Timeline