[14:13:51] <nedbat> "russianidiot" seems to be typo-squatting a number of packages, like https://pypi.python.org/pypi/request/0.0.22
[14:18:04] <pombreda> nedbat, I wonder if this is evil squatting: it has been around for a long time. But this is squatting nonetheless
[14:18:36] <nedbat> pombreda: well, i can't figure out why they are bothering, since the code doesn't seem to do anything useful, even maliciously.
[14:19:01] <nedbat> pombreda: but if you look at their github, they have a few repos designed to be installed needlessly by mistake (pip install dict)?
[14:19:31] <pombreda> this is the most peculiar set of repos I have ever seen
[14:21:18] <pombreda> nedbat, like it had been written by someone with some serious obsession or a very different mind
[14:23:50] <pombreda> nedbat, I do not think this is evil, just annoying. And the work of person with a very different mind, to say the least and staying PC :P
[15:37:40] <toad_polo> Why do you think this is not malicious?
[15:38:08] <toad_polo> The weird separation into a bunch of different packages seems like kind of hallmark of code obfuscation.
[15:40:02] <toad_polo> Though I dunno, putting everything on github and setting up codecov and stuff does make you think they're just a person who is a bit off and has a funky way of organizing things.
[15:41:09] <toad_polo> The fact that GET pulls stuff from an environment variable and does stuff with it that I need to go a few repos deep to unravel is not encouraging, though.
[16:15:28] <pombreda> toad_polo, I think this is not malicious because I have seen packages from this russianiodiot for several years and they look as harmless as they can. Some do real things, several do not do much at all
[16:15:52] <pombreda> this is mostly junk but not malicious code IMHO
[16:15:59] <pombreda> from someone that is likely sick
[16:16:09] <pombreda> in the very real sense of the word
[16:16:09] <nedbat> toad_polo: if you "pip install request", it doesn't do anything. It fails on a name error about "get".
[16:17:38] <pombreda> toad_polo, and if not sick, that person is very much off, south and north :)