-= Per source details. Do not edit below this line.=-
During the installation, the package iterates its files and attempts to import a hidden module - which is embedded as ZIP archive in the image file
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-12-handyfiles
Reasons (based on the campaign):
The package overrides the install command in setup.py to execute malicious code during installation.
obfuscation
{
"malicious-packages-origins": [
{
"import_time": "2025-12-02T22:30:55.235301379Z",
"modified_time": "2024-12-24T17:49:23Z",
"sha256": "ff07706cf12a9e367be39e539835ae8ee32652676ab1837588447db7871e60bb",
"source": "kam193",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"id": "pypi/2024-12-handyfiles/handyfiles"
},
{
"import_time": "2025-12-02T23:07:18.257293387Z",
"modified_time": "2024-12-24T17:49:23Z",
"sha256": "381cd796d4e5fce8fb62c337374b5303e0b2466d67467efc95cbc4d7d8248dd4",
"source": "kam193",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"id": "pypi/2024-12-handyfiles/handyfiles"
},
{
"import_time": "2025-12-10T21:38:57.520858731Z",
"modified_time": "2024-12-24T17:49:23Z",
"sha256": "7efccb64b4cdd8fb7874c44d3a4fc5d80cfcb38076c5bf26250310dddef5d4ee",
"source": "kam193",
"versions": [
"0.0.1"
],
"id": "pypi/2024-12-handyfiles/handyfiles"
}
]
}