<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from ossf_malicious_packages</title>
    <link>https://127.0.0.1:10001</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:18:37 +0000</lastBuildDate>
    <item>
      <title>mal-2026-17471</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17471</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c0d27d780e356c6ae75dedaa144f2064476e275a02f801a1d56897a3a9d1930f)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c0d27d780e356c6ae75dedaa144f2064476e275a02f801a1d56897a3a9d1930f)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17471</guid>
      <pubDate>Sat, 03 Oct 2026 19:41:50 +0000</pubDate>
    </item>
    <item>
      <title>mal-2026-17469</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17469</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (4abc7154004498e9054ca8ac239acd73ab86815f6029ad5d52e4c883488f4c70)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (4abc7154004498e9054ca8ac239acd73ab86815f6029ad5d52e4c883488f4c70)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17469</guid>
      <pubDate>Sat, 03 Oct 2026 16:21:40 +0000</pubDate>
    </item>
    <item>
      <title>mal-2026-17470</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17470</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (12f18950a276ca27a304d3053835b0102656168083e7ddf414fffb112cbe01ba)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (12f18950a276ca27a304d3053835b0102656168083e7ddf414fffb112cbe01ba)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17470</guid>
      <pubDate>Sat, 03 Oct 2026 14:42:59 +0000</pubDate>
    </item>
    <item>
      <title>mal-2026-17468</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17468</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (28ef552864bd4b4558137163734077a2429281647a26868f40d8d735af95c967)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (28ef552864bd4b4558137163734077a2429281647a26868f40d8d735af95c967)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17468</guid>
      <pubDate>Sat, 03 Oct 2026 14:00:06 +0000</pubDate>
    </item>
    <item>
      <title>mal-2026-17465</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17465</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (18746c0b1bc840ee608e3aba81f9e18e4411373b8993d315177e95614fe67b08)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (18746c0b1bc840ee608e3aba81f9e18e4411373b8993d315177e95614fe67b08)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17465</guid>
      <pubDate>Sat, 03 Oct 2026 13:18:34 +0000</pubDate>
    </item>
    <item>
      <title>mal-2026-17466</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17466</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (92a0735c100233f803adcf4cec20645acbb5f01b1757e8889dfaa631e49dae71)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (92a0735c100233f803adcf4cec20645acbb5f01b1757e8889dfaa631e49dae71)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17466</guid>
      <pubDate>Sat, 03 Oct 2026 12:24:50 +0000</pubDate>
    </item>
    <item>
      <title>mal-2026-17467</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17467</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c0f6ddfc6a324d42219bbea8405be17115f83eca0e2d2eecb4e3fe6b6ec3dbde)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c0f6ddfc6a324d42219bbea8405be17115f83eca0e2d2eecb4e3fe6b6ec3dbde)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17467</guid>
      <pubDate>Sat, 03 Oct 2026 11:51:12 +0000</pubDate>
    </item>
    <item>
      <title>mal-2026-17464</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17464</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (5050cd1cac91a217e828de6f54792051b810c43bf9ee5d53e913479fb059715c)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (5050cd1cac91a217e828de6f54792051b810c43bf9ee5d53e913479fb059715c)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17464</guid>
      <pubDate>Sat, 03 Oct 2026 10:46:57 +0000</pubDate>
    </item>
    <item>
      <title>mal-2026-17462</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17462</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c38ef1a445f502de507bc9e58f66539c816eb765a086e14631bd164bc501a644)
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.


---

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research &amp; co, with clearly low-harm possibilities.


Campaign: GENERIC-standard-pypi-install-pentest


Reasons (based on the campaign):


 - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.


 - The package overrides the install command in setup.py to execute malicious code during installation.
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c38ef1a445f502de507bc9e58f66539c816eb765a086e14631bd164bc501a644)
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.


---

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research &amp; co, with clearly low-harm possibilities.


Campaign: GENERIC-standard-pypi-install-pentest


Reasons (based on the campaign):


 - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.


 - The package overrides the install command in setup.py to execute malicious code during installation.
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17462</guid>
      <pubDate>Sat, 03 Oct 2026 05:03:06 +0000</pubDate>
    </item>
    <item>
      <title>mal-2026-17463</title>
      <link>https://127.0.0.1:10001/vuln/mal-2026-17463</link>
      <description>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (382411a9cc0ee358dbd8efcf17c5a943fc496fc4f2c86ffdc8f87d7efc43ec2d)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</description>
      <content:encoded>
---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (382411a9cc0ee358dbd8efcf17c5a943fc496fc4f2c86ffdc8f87d7efc43ec2d)
The package imitates real activity and instead deploys a coin miner.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-voxeval


Reasons (based on the campaign):


 - cryptominer
</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/mal-2026-17463</guid>
      <pubDate>Sat, 03 Oct 2026 04:47:46 +0000</pubDate>
    </item>
  </channel>
</rss>
