-= Per source details. Do not edit below this line.=-
Importing the module starts exfiltrating Discord tokens
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-11-morosint
Reasons (based on the campaign):
exfiltration-browser-data
exfiltration-credentials
{
"iocs": {
"urls": [
"https://canary.discord.com/api/webhooks/1438273237867036682/y-jlMJWQRYZlxmYEAzEKNQLMRG3GTh7ZcVryf-CpYulJymcNV_rXJMFtvIDke7E7w5HW",
"https://canary.discord.com/api/webhooks/1437951747627815105/pye5awwKpavmOnp0tOfLosFBXM-mRTX1rSQFTMBOWiNMJ9FZYvcOYRYS331jO7WSyWVL"
]
},
"malicious-packages-origins": [
{
"versions": [
"0.0.1"
],
"modified_time": "2025-11-12T23:24:39.569177Z",
"sha256": "0ea2b4d8a9da73a4027151f88b37267ed5b44d14b635c6e78f95172effe47129",
"id": "pypi/2025-11-morosint/morosint",
"source": "kam193",
"import_time": "2025-12-02T22:30:55.347104273Z"
},
{
"versions": [
"0.0.1"
],
"modified_time": "2025-11-12T23:24:39.569177Z",
"sha256": "2118ab70535d0272c108e5a454745ae83d10cd3421d5989984ab961b348367b5",
"id": "pypi/2025-11-morosint/morosint",
"source": "kam193",
"import_time": "2025-12-02T23:07:18.377362815Z"
}
]
}