-= Per source details. Do not edit below this line.=-
Malicious clone of a legitimate "loguru" package. There is added code to download and run an executable. Sandbox analysis reveals attempts to steal browsers data
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-11-logguru
Reasons (based on the campaign):
clones-real-package
Downloads and executes a remote executable.
infostealer
typosquatting
{
"malicious-packages-origins": [
{
"modified_time": "2025-11-29T13:47:21.627066Z",
"source": "kam193",
"import_time": "2025-12-02T22:30:55.315382962Z",
"id": "pypi/2025-11-logguru/logguru",
"versions": [
"0.7.3",
"0.7.4",
"0.7.5",
"0.7.6",
"0.7.7",
"0.7.8"
],
"sha256": "9e2280b7c5a7387c1ff2dc26dcead820f65ffddbd638f67fd653d55a70838232"
},
{
"modified_time": "2025-11-29T13:47:21.627066Z",
"source": "kam193",
"import_time": "2025-12-02T23:07:18.342230401Z",
"id": "pypi/2025-11-logguru/logguru",
"versions": [
"0.7.3",
"0.7.4",
"0.7.5",
"0.7.6",
"0.7.7",
"0.7.8"
],
"sha256": "64b91d48504c05711a759a1cb2a0bfd63650f47d05d04296bbea6269ed4229b4"
}
],
"iocs": {
"ips": [
"64.188.79.157"
],
"urls": [
"https://64.188.79.157:443/new"
]
}
}