Skip to content

PROBABLY_PENTEST (1) campaign cataloged at 2026-08-09(2).

  1. Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-08-cubesat-upstream-driver

Package appears to abuse PyPI for a CTF-like exercise. It can collect up to all environment variables. The package does not exfiltrate them on its own, suggesting there is another external trigger for that.

Originally detected by Aikido.

Abuse categories

dependency-confusion

An attempt to exploit dependency confusion

other

Campaign uses other.

Packages in the campaign

campaign:2026-08-cubesat-upstream-driver