-= Per source details. Do not edit below this line.=-
During installation, package installs a script that listens for remote commands and executes them. The script is also added to autostart configuration and disguised as system application. This package also adds a new SSH keys for further persistence
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-02-devtools-webhook-cicd-utils
Reasons (based on the campaign):
The package overrides the install command in setup.py to execute malicious code during installation.
peristence-autorun
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
obfuscation
2.1.0Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H