-= Per source details. Do not edit below this line.=-
Importing the module starts executing a remote script, as well as leaves a persitance in the .bashrc
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2023-12-09-papiculo
Reasons (based on the campaign):
{
"iocs": {
"domains": [
"papiculo.net"
],
"urls": [
"https://gitlab.com/fajarranz19/work/-/raw/main/lol1.78"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2023-12-09-papiculo/driftme",
"import_time": "2025-12-02T22:30:55.11440008Z",
"modified_time": "2024-11-29T18:14:43Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "4bc96d0149e984cf93e1b7bf15de1918088cb524539497e12646f4836b5ae4b0",
"source": "kam193"
},
{
"id": "pypi/2023-12-09-papiculo/driftme",
"import_time": "2025-12-02T23:07:18.125989478Z",
"modified_time": "2024-11-29T18:14:43Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "4db40025175947d42bcca75bc2f04d0dab05379e9e84108c40de1cda6a854604",
"source": "kam193"
},
{
"id": "pypi/2023-12-09-papiculo/driftme",
"import_time": "2025-12-10T21:38:57.410585504Z",
"modified_time": "2024-11-29T18:14:43Z",
"sha256": "2cfc67b42dd19cf0e9806f3cf07789e0d7eec73b71e129275aad42b220655dbc",
"source": "kam193",
"versions": [
"1.0"
]
}
]
}