-= Per source details. Do not edit below this line.=-
Every time the user sends a message to the AI, the user IP, message as well as the response are exfiltrated to a hardcoded telegram channel. This behaviour is not mentioned in the package description. Instead, the description lures to offer advanced features.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-09-spider-ai
Reasons (based on the campaign):
exfiltration-generic
A Telegram webhook is used to send collected data.
action-hidden-in-lib-usage
{
"malicious-packages-origins": [
{
"source": "kam193",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "751c9eeed2ec7246092237af521e06377fe0899fe815c11175a8cac1195d47c1",
"import_time": "2025-12-02T22:30:55.61039607Z",
"modified_time": "2024-10-02T09:16:00Z",
"id": "pypi/2024-09-spider-ai/spy-ai"
},
{
"source": "kam193",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "d71096c3aa8cb143ba7fab208ab313a240e8f1f9846b17b947a01f729fc1864a",
"import_time": "2025-12-02T23:07:18.650248484Z",
"modified_time": "2024-10-02T09:16:00Z",
"id": "pypi/2024-09-spider-ai/spy-ai"
},
{
"source": "kam193",
"sha256": "1f14a74be2a5dc314937cc2e527ac9bb1b3d76c633b6d3bdfc72dfce460f7db6",
"versions": [
"1.0",
"1.1",
"0.1",
"1.1.0",
"1.0.0",
"0.1.3",
"1.0.1",
"1.1.3",
"1.1.1"
],
"import_time": "2025-12-10T21:38:57.84021012Z",
"modified_time": "2024-10-02T09:16:00Z",
"id": "pypi/2024-09-spider-ai/spy-ai"
},
{
"source": "kam193",
"sha256": "9d5643ef1befe879e71d0d23d1827a7d8c333323bfec1e60b2653643f43f57f2",
"versions": [
"0.1",
"0.1.3",
"1.0",
"1.0.0",
"1.0.1",
"1.1",
"1.1.0",
"1.1.1",
"1.1.3"
],
"import_time": "2025-12-30T22:39:04.186501234Z",
"modified_time": "2024-10-02T09:16:00Z",
"id": "pypi/2024-09-spider-ai/spy-ai"
}
],
"iocs": {
"domains": [
"01d73592-4d64-43f7-b664-ecd679686756-00-30a5f50srzeko.janeway.replit.dev"
]
}
}