-= Per source details. Do not edit below this line.=-
Importing the module downloads and starts an infostealer attempting to exfiltrate data and establishing persistence through autorun directory.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-12-reqesst
Reasons (based on the campaign):
infostealer
peristence-autorun
typosquatting
exfiltration-generic
Downloads and executes a remote executable.
clones-real-package
dependency-confusion
exfiltration-browser-data
exfiltration-crypto
{
"malicious-packages-origins": [
{
"sha256": "d770e81fd292e7197f38c6d0ae24eba80b80b257f7f1f62901f4f56ad1360af4",
"source": "kam193",
"modified_time": "2024-12-24T18:09:49Z",
"id": "pypi/2024-12-reqesst/requesr",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.534787915Z"
},
{
"sha256": "b792f17b467610a1021820a7718884aa436487a9ec75d5ebf889d400efeaec24",
"source": "kam193",
"modified_time": "2024-12-24T18:09:49Z",
"id": "pypi/2024-12-reqesst/requesr",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.573078823Z"
},
{
"sha256": "ab3aac1ba180fd7c8e4a17edeb7a4e7a8345d73f342e5e78751910ca2876e85c",
"source": "kam193",
"modified_time": "2024-12-24T18:09:49Z",
"id": "pypi/2024-12-reqesst/requesr",
"versions": [
"2.32.3",
"2.32.2"
],
"import_time": "2025-12-10T21:38:57.78182982Z"
},
{
"sha256": "a1ee8dfb075ecc00ec6f59ffc7500417dc3f1837ff205d96d7dc9a7d9fb817d0",
"source": "kam193",
"modified_time": "2024-12-24T18:09:49Z",
"id": "pypi/2024-12-reqesst/requesr",
"versions": [
"2.32.2",
"2.32.3"
],
"import_time": "2025-12-30T22:39:04.16079217Z"
}
],
"iocs": {
"urls": [
"https://www.dropbox.com/scl/fi/d4ftoxxvovr12f4tjh0mc/H7Glqp2Vy.exe?rlkey=z323u7r1ipm2tegn2dqlqzv9l&st=9gg48qpa&dl=1"
]
}
}