Malicious code in d0rk3r (PyPI)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (1cbc673402f814b065eadc8be2641d761d482c30722fdd8e6b1b7522fde2f478) d0rk3r 1.0.5 is advertised as a Shodan IP scraper with proxy rotation, but the sdist ships no Python source — only LICENSE, README, pyproject.toml, requirements.txt, MANIFEST.in, setup.cfg, and egg-info metadata. The package directory `d0rk3r_pkg/` referenced by `[project.scripts] d0rk3r = d0rk3r_pkg.cli:main` and by `[tool.setuptools.packages.find]` is missing from the tarball, so installing this sdist provides no working `d0rk3r` console script. pyproject.toml line 32 declares a mandatory dependency on `d0rk3r-telemetry>=1.0.0` (open-ended lower bound), which is not mentioned in README or PKG-INFO. The combination — empty functional shell, undisclosed dependency whose name advertises data collection, and an unpinned floor that lets the author change the dependency's behavior at any time — means the entire effect of `pip install d0rk3r` is to pull in the sibling package. Whether that sibling is benign telemetry or an exfil/dropper cannot be determined from this package alone; the sibling tarball needs to be analyzed directly. Routing to human review so the d0rk3r-telemetry package can be examined before a public verdict is issued. ## Source: kam193 (d0d4cf20ac250e3d7a23666cf8bc3ae722d555b982649dad3f615d9c7c8818d9) The package declares malicious dependencies. Their activity is however not triggered as since version 1.0.4, the packages releases lack any source code. Malicious dependency was first introduced in version 1.0.5, but the package is likely prepared to be a loader of malicious code from very begining. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-request-cache-py Reasons (based on the campaign): - infostealer - exfiltration-env-variables - exfiltration-ssh-keys - impersonation - A Telegram webhook is used to send collected data. - exfiltration-browser-data - The package contains code to detect if it is running in a sandbox environment. - exfiltration-credentials - The malicious code is intentionally included in a dependency of the package
AI Analysis
Technical Summary
The 'd0rk3r' PyPI package (versions 1.0.0 to 1.2.0) is a malicious package that acts as a loader for harmful code via an undisclosed mandatory dependency 'd0rk3r-telemetry'. The package releases since version 1.0.4 contain no functional source code, only metadata and configuration files, making the dependency the actual vector for malicious activity. The malicious payload includes infostealing capabilities targeting environment variables, SSH keys, browser data, and credentials, with exfiltration conducted through a Telegram webhook. The package also attempts to detect sandbox environments to avoid detection. This behavior indicates a deliberate attempt to disguise malicious intent by splitting functionality into dependencies.
Potential Impact
Installation of the 'd0rk3r' package results in the automatic installation of a malicious dependency that can steal sensitive information such as environment variables, SSH keys, browser data, and credentials. The stolen data is exfiltrated via a Telegram webhook, potentially compromising user systems and data confidentiality. The package's sandbox detection may hinder analysis and delay detection. This poses a significant risk of data breach and unauthorized access for users who install this package.
Mitigation Recommendations
No official patch or fix is available for this malicious package. Users should avoid installing 'd0rk3r' versions 1.0.0 through 1.2.0 from PyPI. Audit and remove any installations of this package and its dependencies from environments. Monitor for any suspicious activity related to data exfiltration. Since the malicious code is in a dependency, scrutinize all dependencies of installed packages. Consider using package allowlists and verifying package integrity before installation.
Malicious code in d0rk3r (PyPI)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (1cbc673402f814b065eadc8be2641d761d482c30722fdd8e6b1b7522fde2f478) d0rk3r 1.0.5 is advertised as a Shodan IP scraper with proxy rotation, but the sdist ships no Python source — only LICENSE, README, pyproject.toml, requirements.txt, MANIFEST.in, setup.cfg, and egg-info metadata. The package directory `d0rk3r_pkg/` referenced by `[project.scripts] d0rk3r = d0rk3r_pkg.cli:main` and by `[tool.setuptools.packages.find]` is missing from the tarball, so installing this sdist provides no working `d0rk3r` console script. pyproject.toml line 32 declares a mandatory dependency on `d0rk3r-telemetry>=1.0.0` (open-ended lower bound), which is not mentioned in README or PKG-INFO. The combination — empty functional shell, undisclosed dependency whose name advertises data collection, and an unpinned floor that lets the author change the dependency's behavior at any time — means the entire effect of `pip install d0rk3r` is to pull in the sibling package. Whether that sibling is benign telemetry or an exfil/dropper cannot be determined from this package alone; the sibling tarball needs to be analyzed directly. Routing to human review so the d0rk3r-telemetry package can be examined before a public verdict is issued. ## Source: kam193 (d0d4cf20ac250e3d7a23666cf8bc3ae722d555b982649dad3f615d9c7c8818d9) The package declares malicious dependencies. Their activity is however not triggered as since version 1.0.4, the packages releases lack any source code. Malicious dependency was first introduced in version 1.0.5, but the package is likely prepared to be a loader of malicious code from very begining. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-request-cache-py Reasons (based on the campaign): - infostealer - exfiltration-env-variables - exfiltration-ssh-keys - impersonation - A Telegram webhook is used to send collected data. - exfiltration-browser-data - The package contains code to detect if it is running in a sandbox environment. - exfiltration-credentials - The malicious code is intentionally included in a dependency of the package
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'd0rk3r' PyPI package (versions 1.0.0 to 1.2.0) is a malicious package that acts as a loader for harmful code via an undisclosed mandatory dependency 'd0rk3r-telemetry'. The package releases since version 1.0.4 contain no functional source code, only metadata and configuration files, making the dependency the actual vector for malicious activity. The malicious payload includes infostealing capabilities targeting environment variables, SSH keys, browser data, and credentials, with exfiltration conducted through a Telegram webhook. The package also attempts to detect sandbox environments to avoid detection. This behavior indicates a deliberate attempt to disguise malicious intent by splitting functionality into dependencies.
Potential Impact
Installation of the 'd0rk3r' package results in the automatic installation of a malicious dependency that can steal sensitive information such as environment variables, SSH keys, browser data, and credentials. The stolen data is exfiltrated via a Telegram webhook, potentially compromising user systems and data confidentiality. The package's sandbox detection may hinder analysis and delay detection. This poses a significant risk of data breach and unauthorized access for users who install this package.
Mitigation Recommendations
No official patch or fix is available for this malicious package. Users should avoid installing 'd0rk3r' versions 1.0.0 through 1.2.0 from PyPI. Audit and remove any installations of this package and its dependencies from environments. Monitor for any suspicious activity related to data exfiltration. Since the malicious code is in a dependency, scrutinize all dependencies of installed packages. Consider using package allowlists and verifying package integrity before installation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6246
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4f6c3668715ace43158714
Added to database: 07/09/2026, 09:39:02 UTC
Last enriched: 07/10/2026, 12:09:54 UTC
Last updated: 07/29/2026, 04:37:40 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.