-= Per source details. Do not edit below this line.=-
Importing the module starts an infostealer
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-11-mescouilles
Reasons (based on the campaign):
infostealer
infostealer:kiwi
infostealer:cstealer
exfiltration-generic
exfiltration-browser-data
exfiltration-credentials
files-exfiltration
The package contains code to detect if it is running in a sandbox environment.
{
"malicious-packages-origins": [
{
"sha256": "e998d7ff65c4a84a2a570510eac3f440b97f22877312abeb234803babaf8fd20",
"source": "kam193",
"modified_time": "2025-11-24T21:58:24.80598Z",
"id": "pypi/2025-11-mescouilles/aiostreams",
"versions": [
"0.0.1"
],
"import_time": "2025-12-02T22:30:54.893542955Z"
},
{
"sha256": "a6bc4c2d12a8ad24e8844bea0287de82e1e6ab24b08fb1f5ac983c0906a655d9",
"source": "kam193",
"modified_time": "2025-11-24T21:58:24.80598Z",
"id": "pypi/2025-11-mescouilles/aiostreams",
"versions": [
"0.0.1"
],
"import_time": "2025-12-02T23:07:17.937541516Z"
},
{
"sha256": "cb88717713d2cfea9c802c72e9939fd55a3d3ae6db8a8f8ae88c9f0377a73335",
"source": "reversing-labs",
"modified_time": "2025-12-23T08:37:53Z",
"id": "RLMA-2025-06550",
"versions": [
"0.0.1"
],
"import_time": "2025-12-24T10:07:30.041628158Z"
},
{
"sha256": "b6fd3158674e546ccd09121f039317c167a1adae62404b9fe99760f0c252adca",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:10:50Z",
"id": "RLUA-2026-00048",
"import_time": "2026-03-19T12:19:21.22988148Z"
}
],
"iocs": {
"domains": [
"honey.zakura-int.workers.dev"
],
"urls": [
"https://discord.com/api/webhooks/1438590458204000289/GoNmnNIWqcL152FVm8uszof971e2NnyNjsO4j_o4ZJuP9AhMaaR5XBEkkYcKP1GBcouo",
"https://discord.com/api/webhooks/1113937838837346429/iG7DEPvhfOdswri8SyWslR4bZY-XV-kOyQlwrUt_yOOMowuExGYAPnnHEO60XTfYt6VJ",
"https://pastebin.com/raw/vb608t9D"
]
}
}