-= Per source details. Do not edit below this line.=-
During the installation, the package iterates its files and attempts to import a hidden module - which is embedded as ZIP archive in the image file
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-12-handyfiles
Reasons (based on the campaign):
The package overrides the install command in setup.py to execute malicious code during installation.
obfuscation
{
"malicious-packages-origins": [
{
"source": "kam193",
"modified_time": "2024-12-24T17:49:23Z",
"sha256": "e254f88b8d741f7a43a0e494dcfd08135f29b5634f3baa5d684b2bd6bc168bfc",
"id": "pypi/2024-12-handyfiles/filecraft",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.193250093Z"
},
{
"source": "kam193",
"modified_time": "2024-12-24T17:49:23Z",
"sha256": "3d0eec02526b659b5e856c211e05be1842dc283ed0b7d07dc90574ea5c7dc34a",
"id": "pypi/2024-12-handyfiles/filecraft",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.202363358Z"
},
{
"versions": [
"0.0.1"
],
"modified_time": "2024-12-24T17:49:23Z",
"sha256": "3cc26897a4e79c8a9b10f1b628671a7e2af53733c3bc7ee8ca5eecdc6c97f450",
"id": "pypi/2024-12-handyfiles/filecraft",
"source": "kam193",
"import_time": "2025-12-10T21:38:57.487552343Z"
}
]
}