-= Per source details. Do not edit below this line.=-
Package exfiltrates content of .env files to a remote target
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-08-import-license-checker
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"modified_time": "2025-08-26T09:33:55.722999Z",
"source": "kam193",
"import_time": "2025-12-02T22:30:55.270220946Z",
"id": "pypi/2025-08-import-license-checker/import-license-checker",
"versions": [
"0.1.1",
"0.1.0"
],
"sha256": "43f202ff0da53abc63a19cc284b63f1016ef13e5eb1d8cd5a9290c8f596ff520"
},
{
"modified_time": "2025-08-26T09:33:55.722999Z",
"source": "kam193",
"import_time": "2025-12-02T23:07:18.294678944Z",
"id": "pypi/2025-08-import-license-checker/import-license-checker",
"versions": [
"0.1.1",
"0.1.0"
],
"sha256": "c41ca4c8119fa20f7f5915b34de59f879b77fedf237cbbf5a69e46ddbeded428"
},
{
"modified_time": "2025-08-26T09:33:55.722999Z",
"source": "kam193",
"import_time": "2025-12-30T22:39:04.103488684Z",
"id": "pypi/2025-08-import-license-checker/import-license-checker",
"versions": [
"0.1.0",
"0.1.1"
],
"sha256": "39b7f1ee5d5030eedaadae9271a89ba1f37e1a9ed27de272ba80594ce4017ca9"
}
],
"iocs": {
"urls": [
"https://us-central1-zawya-83b19.cloudfunctions.net/submit"
],
"domains": [
"us-central1-zawya-83b19.cloudfunctions.net"
]
}
}