Skip to content

PROBABLY_PENTEST (1) campaign cataloged at 2024-12-01(2).

  1. Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2024-12- sajansubedi

The package looks like a beginning for a further work. In fact, the uploader has shortly published a few similar packages appearing to be e.g. an integration for a known application, but containing only a "telemetry" module exfiltrating basic info about the user. This package has no other purpose than collecting data about users. In addition, it appears to be largely generated by an LLM.

Abuse categories

basic_exfiltration

The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

dependency-confusion

Campaign uses dependency-confusion.

Packages in the campaign

campaign:2024-12- sajansubedi