-= Per source details. Do not edit below this line.=-
Importing the module starts an obfuscated PowerShell code, which downloads and executes a remote script. On Windows, the script appears to just start the calculator. On MacOS, the file is identified as a Spark RAT by multiple vendors. Package impersonate the legitimate "python-bitget".
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-12-python-bitget-api
Reasons (based on the campaign):
typosquatting
obfuscation
clones-real-package
dependency-confusion
crypto-related
impersonation
Downloads and executes a remote malicious script.
{
"iocs": {
"urls": [
"https://dl.dropboxusercontent.com/scl/fi/bkhek6zqbo0cqgboteegj/1.txt?rlkey=yn18m53jayba4e3m5bdi02czm&st=eh1edmf0&dl=0",
"https://dl.dropboxusercontent.com/scl/fi/6hg0a8fg9m36eahv88rwo/template?rlkey=0vkaw44mh3gak6y82l4ht39zg&st=ygbc7qgh&dl=0"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2024-12-python-bitget-api/python-bitget-api",
"import_time": "2025-12-02T22:30:55.487507567Z",
"modified_time": "2024-12-12T21:48:47Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "a5fe8ca96d7c776e6075d499136bb772e611074714fe83f965c747eb653b6abc",
"source": "kam193"
},
{
"id": "pypi/2024-12-python-bitget-api/python-bitget-api",
"import_time": "2025-12-02T23:07:18.512786121Z",
"modified_time": "2024-12-12T21:48:47Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "cac6988c3746b27c0cc34a156657431c2a0c0c36de45c6b88a00130d30dfd66e",
"source": "kam193"
},
{
"id": "pypi/2024-12-python-bitget-api/python-bitget-api",
"import_time": "2025-12-10T21:38:57.724026949Z",
"modified_time": "2024-12-12T21:48:47Z",
"sha256": "29ef7b696db534499045bf5afb8add3b248725e4dd618427f691ace7e0a88929",
"source": "kam193",
"versions": [
"3.1.5",
"3.3.5"
]
}
]
}