-= Per source details. Do not edit below this line.=-
Infostealer exfiltrating cookies, history and passwords from the Google Chrome browser, as well as attempting to do a webcam photo. Data are sent to a Discord webhook. Malicious code is split over multiple files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-08-old-threading-assistant
Reasons (based on the campaign):
infostealer
typosquatting
{
"malicious-packages-origins": [
{
"source": "kam193",
"id": "pypi/2024-08-old-threading-assistant/threading-assistant",
"modified_time": "2024-08-19T09:59:22Z",
"sha256": "94c681cc1f469c5e74cf129c4a7cc37602b47bcad02857e98d278b8a1f5f25c6",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.644136633Z"
},
{
"source": "kam193",
"id": "pypi/2024-08-old-threading-assistant/threading-assistant",
"modified_time": "2024-08-19T09:59:22Z",
"sha256": "b7b431362a8fc3af245e62278011eb007f0b23eeaa959c3a34bbb959fa549a4c",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.686079865Z"
},
{
"source": "kam193",
"id": "pypi/2024-08-old-threading-assistant/threading-assistant",
"modified_time": "2024-08-19T09:59:22Z",
"sha256": "41ce19661f27267642c2cd2098c7e7d5f0bdb39bae5ddbf60f97482f78e40e6e",
"versions": [
"0.1"
],
"import_time": "2025-12-12T12:11:30.637847201Z"
}
]
}