-= Per source details. Do not edit below this line.=-
Package downloads and runs an obfuscated bat file, which executes malicious activity according to VirusTotal results.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-10-windowsrequir
Reasons (based on the campaign):
impersonation
Downloads and executes a remote malicious script.
malware
{
"malicious-packages-origins": [
{
"versions": [
"0.1.0"
],
"source": "reversing-labs",
"import_time": "2025-12-02T09:09:37.720137174Z",
"modified_time": "2025-12-01T12:54:30Z",
"id": "RLMA-2025-05609",
"sha256": "e82ea3bfe177e3a52180f82acba72f98c9b10f04e97ea0ae8dc74d1c004ca45d"
},
{
"versions": [
"0.1.1",
"0.1.0"
],
"source": "kam193",
"import_time": "2025-12-02T22:30:55.275123728Z",
"modified_time": "2025-10-29T21:52:42.690983Z",
"id": "pypi/2025-10-windowsrequir/install-all-setup",
"sha256": "03401206aa55bda1cc26afad6203380a749c97da2240e9569300d7e521a8d91a"
},
{
"versions": [
"0.1.1",
"0.1.0"
],
"source": "kam193",
"import_time": "2025-12-02T23:07:18.299427363Z",
"modified_time": "2025-10-29T21:52:42.690983Z",
"id": "pypi/2025-10-windowsrequir/install-all-setup",
"sha256": "519885ab1e79055139dd279d8e9bf603b4f1d0c0f3f6d3c90231c934f26bbb60"
},
{
"versions": [
"0.1.0",
"0.1.1"
],
"source": "kam193",
"import_time": "2025-12-30T22:39:04.105666566Z",
"modified_time": "2025-10-29T21:52:42.690983Z",
"id": "pypi/2025-10-windowsrequir/install-all-setup",
"sha256": "e8a9d972780917c906493881066e1cc7bce18f30732f1b8e8b65b708630fdb0d"
},
{
"versions": [
"0.1.1"
],
"source": "reversing-labs",
"import_time": "2026-03-19T12:19:55.008139043Z",
"modified_time": "2026-03-18T12:15:04Z",
"id": "RLUA-2026-00426",
"sha256": "52619318269cf4f857dcfb1bbd7003ad52d53fea1cd7e7b74fd0271eb961366e"
}
],
"iocs": {
"urls": [
"http://stellar-conquest.fr/launcher.bat"
],
"domains": [
"stellar-conquest.fr"
]
}
}