-= Per source details. Do not edit below this line.=-
Infostealer exfiltrating cookies, history and passwords from the Google Chrome browser, as well as attempting to do a webcam photo. Data are sent to a Discord webhook. Malicious code is split over multiple files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-08-old-threading-assistant
Reasons (based on the campaign):
infostealer
typosquatting
{
"malicious-packages-origins": [
{
"sha256": "6b5a7641101403d95e625db9e27ebbb1caa4bba91a70daf75f3997e10e7f78fa",
"source": "kam193",
"modified_time": "2024-08-19T09:59:22Z",
"id": "pypi/2024-08-old-threading-assistant/assisting-threading",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:54.945757133Z"
},
{
"sha256": "33605e5f943eacd5d5ab7a4c37625226e2ef072f2fd3dac068b169d58ba1c2c9",
"source": "kam193",
"modified_time": "2024-08-19T09:59:22Z",
"id": "pypi/2024-08-old-threading-assistant/assisting-threading",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:17.985182926Z"
},
{
"sha256": "55be697852195e9e6a2c823e40b85399a0cae73a5a61c79787a3639eebe86018",
"source": "kam193",
"modified_time": "2024-08-19T09:59:22Z",
"id": "pypi/2024-08-old-threading-assistant/assisting-threading",
"versions": [
"0.1"
],
"import_time": "2025-12-10T21:38:57.290958698Z"
}
]
}