SafeDep
Install GitHub App

Summary

Package contains suspicious powershell URL, an obfuscated executable with fake headers, indicating malicious intent.

Verification Record

No verification record available.

Details

The package exhibits multiple suspicious characteristics. First, the METADATA file contains a YARA match for http_url_with_powershell, indicating a potential attempt to download and execute PowerShell scripts, which is often used for malicious purposes. Second, the package includes an embedded executable file (ruff-0.14.6.data/scripts/ruff). Third, this executable is flagged by YARA rules as an 'obfuscated_elf' and having 'fake_section_headers_conflicting_entry_point_address'. Obfuscation and fake headers are common techniques used by malware to evade detection. The combination of these factors strongly suggests that the package is malicious.

ruff@0.14.6Suspicious
Unverified
Analysed at: 11/21/25, 2:25 PM
Source: https://files.pythonhosted.org/packages/67/d2/7dd544116d107fffb24a0064d41a5d2ed1c9d6372d142f9ba108c8e39207/ruff-0.14.6-py3-none-linux_armv6l.whl
SHA256: d724ac2f1c240dbd01a2ae98db5d1d9a5e1d9e96eba999d1c48e30062df578a3
Confidence: Medium