d0rk3rPyPI
Malicious code in d0rk3r (PyPI) Remove it immediately and rotate any exposed credentials.
What this malware does
d0rk3r 1.0.5 is advertised as a Shodan IP scraper with proxy rotation, but the sdist ships no Python source — only LICENSE, README, pyproject.toml, requirements.txt, MANIFEST.in, setup.cfg, and egg-info metadata. The package directory d0rk3r_pkg/ referenced by [project.scripts] d0rk3r = d0rk3r_pkg.cli:main and by [tool.setuptools.packages.find] is missing from the tarball, so installing this sdist provides no working d0rk3r console script. pyproject.toml line 32 declares a mandatory dependency on d0rk3r-telemetry>=1.0.0 (open-ended lower bound), which is not mentioned in README or PKG-INFO. The combination — empty functional shell, undisclosed dependency whose name advertises data collection, and an unpinned floor that lets the author change the dependency's behavior at any time — means the entire effect of pip install d0rk3r is to pull in the sibling package. Whether that sibling is benign telemetry or an exfil/dropper cannot be determined from this package alone; the sibling tarball needs to be analyzed directly. Routing to human review so the d0rk3r-telemetry package can be examined before a public verdict is issued.
The package declares malicious dependencies. Their activity is however not triggered as since version 1.0.4, the packages releases lack any source code. Malicious dependency was first introduced in version 1.0.5, but the package is likely prepared to be a loader of malicious code from very begining.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-request-cache-py
Reasons (based on the campaign):
-
infostealer
-
exfiltration-env-variables
-
exfiltration-ssh-keys
-
impersonation
-
A Telegram webhook is used to send collected data.
-
exfiltration-browser-data
-
The package contains code to detect if it is running in a sandbox environment.
-
exfiltration-credentials
-
The malicious code is intentionally included in a dependency of the package
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Credential / info stealerFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for d0rk3r (16 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging d0rk3r across your stack and pipelines.
If you installed it — respond
d0rk3r is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.
Did it already run?
If d0rk3r was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks d0rk3r before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
- Kamil Mańkowski (kam193) · reporter
Detect & block this
O3 blocks d0rk3r-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.