-= Per source details. Do not edit below this line.=-
During installation, a cryptominer is secretly installed and started.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-09-bondonioanderas-cryptominer
Reasons (based on the campaign):
cryptominer
The package overrides the install command in setup.py to execute malicious code during installation.
obfuscation
{
"iocs": {
"urls": [
"https://raw.githubusercontent.com/MoneroOcean/xmrig_setup/master/setup_moneroocean_miner.sh"
]
},
"malicious-packages-origins": [
{
"id": "RLMA-2024-11163",
"sha256": "a25eb21a3c429a167cb3c50e372745257ebfdf61ae7f503bf947ffdf8601e08e",
"source": "reversing-labs",
"versions": [
"0.1"
],
"modified_time": "2024-12-09T06:51:09Z",
"import_time": "2024-12-09T14:38:48.968351313Z"
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"id": "pypi/2024-09-bondonioanderas-cryptominer/setuptolos",
"sha256": "ade75be64ec274cc6c6769e08e0e7fa010b7307afeb703c9285c5a1541f31f13",
"source": "kam193",
"modified_time": "2024-09-20T11:29:31Z",
"import_time": "2025-12-02T22:30:55.572051127Z"
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"id": "pypi/2024-09-bondonioanderas-cryptominer/setuptolos",
"sha256": "89f6c10eb8edc13e9f46c33bba334822fbb3693527f3fc89714bd86adc3be1af",
"source": "kam193",
"modified_time": "2024-09-20T11:29:31Z",
"import_time": "2025-12-02T23:07:18.613883834Z"
},
{
"id": "pypi/2024-09-bondonioanderas-cryptominer/setuptolos",
"sha256": "425a60f65a70798439baa6844f9ceb51e9f1d2881a7a5992a4fd56d9faf1323f",
"source": "kam193",
"versions": [
"0.1"
],
"modified_time": "2024-09-20T11:29:31Z",
"import_time": "2025-12-10T21:38:57.81407993Z"
},
{
"id": "RLUA-2026-00754",
"sha256": "f83afe9d0289348582512e918db208efeccacf65f5a91b3e356ece01a9cad5ad",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:18:46Z",
"import_time": "2026-03-19T12:20:27.204086469Z"
}
]
}