SafeDep
Install GitHub App

Summary

Multiple YARA matches on embedded executable and powershell endpoint access in METADATA file indicates malicious intent.

Verification Record

No verification record available.

Details

The package exhibits multiple suspicious characteristics. It contains an embedded executable (ruff-0.14.7.data/scripts/ruff), which is further flagged by YARA rules as an obfuscated ELF binary and having fake section headers with a conflicting entry point address. Additionally, the METADATA file contains a YARA match for accessing a hardcoded PowerShell file endpoint. The combination of these factors suggests malicious intent.

ruff@0.14.7Suspicious
Unverified
Analysed at: 11/28/25, 8:55 PM
Source: https://files.pythonhosted.org/packages/8c/b1/7ea5647aaf90106f6d102230e5df874613da43d1089864da1553b899ba5e/ruff-0.14.7-py3-none-linux_armv6l.whl
SHA256: b9d5cb5a176c7236892ad7224bc1e63902e4842c460a0b5210701b13e3de4fca
Confidence: Medium