Skip to content

HIGH_RISK_HACKING_TOOLS (1) package from Python Package Index.

  1. Packages that are very likely to be used to build or as part of a malware, in most cases. They are not malicious on their own, but are quite a good indicator of something suspicious

nspack

Affected versions: (1) 0.1.0, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.8, 0.1.9

  1. Version numbers are usually added automatically. In most cases, the packages listed here were created only to distribute malicious code.

Campaign data

Campaign information may not always be 100% accurate for every related package.

Campaign description

Packages in this campaign seem not to be malicious on their own but altogether create an exfiltration toolkit created by one user, e.g. collecting process data and potentially using DNS as C2. The malicious intention is, however, not confirmed at the moment.

Package nspack additionally notifies upon importing a domain known for malicious activity with the package and hostname.

See more details on the campaign page.

basic_exfiltration

The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

Look up in other services

  1. May not be available. See more in pypi-json-data repository.
  2. Open Source Insights project, provided by Google.
  3. Service from Socket.dev, a cybersecurity company.
  4. Spectra Assure Community, a service from ReversingLabs, a cybersecurity company.
  5. Service from Snyk, a cybersecurity company.