> The project contains a setup.py file that sends a request to a malicious URL during installation.
I can't comment on whether the URL is actually malicious or, perhaps, just logging requests for statistics / tracking.
> The project contains a setup.py file that sends a request to a malicious URL during installation.
I can't comment on whether the URL is actually malicious or, perhaps, just logging requests for statistics / tracking.
The code reads:
url = "http://101.32.99.28/name?<package_name>"
requests.get(url, timeout=30)
So it looks like the author wants to track the number of installs. Nothing is done with the response value (at least for the setup.py that I saw).Edit: seems to be a Tokyo based IP.
Unrelated tidbit: tencent.com returns an empty reply for me at the moment.
That's because the correct address is https://www.tencent.com/ (prefixed with www.)
To test "correctly", you'd likely want to use the requests library or, at the least, ussend the same User-Agent header that it does.
(And, for all we know, they could just be targeting certain IP addresses... or only responding the "malicious" response the first time the URL is requested per IP... or some other weird conditions that we aren't aware of.)