-= Per source details. Do not edit below this line.=-
Package "uconst" is the package containing malicious code with multiple stage, exfiltrating basic info as well as browser data. It's put into others as dependency.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-08-uconst-old
Reasons (based on the campaign):
infostealer
Downloads and executes a remote executable.
The malicious code is intentionally included in a dependency of the package
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
{
"iocs": {
"urls": [
"http://89.23.105.103:809/lin",
"http://89.23.105.103:809/win",
"http://89.23.105.103/eny",
"https://lucky-tubes.000webhostapp.com/log.php?data=sent"
],
"ips": [
"89.23.105.103"
],
"domains": [
"lucky-tubes.000webhostapp.com"
]
},
"malicious-packages-origins": [
{
"id": "RLMA-2024-09455",
"import_time": "2024-10-24T00:57:10.208234888Z",
"sha256": "9175010462ad636ec5813f6478c062e03a63ccb0ee009c3bf01f1db999a40a4a",
"source": "reversing-labs",
"modified_time": "2024-10-16T14:53:17Z",
"versions": [
"1.0.0rc1",
"1.0.0",
"1.0.1",
"1.0.2"
]
},
{
"id": "pypi/2024-08-uconst-old/uconst",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.688016953Z",
"sha256": "8ea8426ed09014407e1aa4060f5913904a0be81975c1b3a9521d8950ac5a303b",
"source": "kam193",
"modified_time": "2024-08-14T22:01:30Z"
},
{
"id": "pypi/2024-08-uconst-old/uconst",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.734297739Z",
"sha256": "cc4ce4d1709ad506513007356fd414ca83c1aa848f9134e952c4b760194428c6",
"source": "kam193",
"modified_time": "2024-08-14T22:01:30Z"
},
{
"id": "pypi/2024-08-uconst-old/uconst",
"import_time": "2025-12-10T21:38:57.906258736Z",
"sha256": "e606007896b8e5ae4cdd0a13e41487b68d5c2c822db34d35fb5d9679bd357f15",
"source": "kam193",
"modified_time": "2024-08-14T22:01:30Z",
"versions": [
"1.0.0"
]
},
{
"id": "RLUA-2026-00869",
"import_time": "2026-03-19T12:20:38.543076082Z",
"sha256": "cd22a2c39c3c613666ec96db47b474c8450f88a91ed4a854b1895310734c5b53",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:19:57Z"
}
]
}