-= Per source details. Do not edit below this line.=-
Package silently exfiltrates user's credentials ahead of starting the promised functionality. First batch used simple code, the newer attempt to hide functionality by using compiled modules
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-07-prof-quotex
Reasons (based on the campaign):
action-hidden-in-lib-usage
A Telegram webhook is used to send collected data.
exfiltration-credentials
{
"malicious-packages-origins": [
{
"source": "kam193",
"modified_time": "2025-07-31T10:01:27.674769Z",
"sha256": "44873829afe6b5a131f37c84d521cc02046d47f11b381452ad2d1887f92a16bb",
"id": "pypi/2025-07-prof-quotex/prof-tg-go-qu",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.444470995Z"
},
{
"source": "kam193",
"modified_time": "2025-07-31T10:01:27.674769Z",
"sha256": "e68d60babccd176fc8f6620e7b711731ff8d6b200d2141b318f1f09482c5a903",
"id": "pypi/2025-07-prof-quotex/prof-tg-go-qu",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.467389869Z"
},
{
"versions": [
"0.0.1"
],
"modified_time": "2025-07-31T10:01:27.674769Z",
"sha256": "aed0c95cbabc81b505c6679a33eef093cf7f4bfc6651ee8121d4ef8c0e175481",
"id": "pypi/2025-07-prof-quotex/prof-tg-go-qu",
"source": "kam193",
"import_time": "2025-12-10T21:38:57.682183025Z"
}
]
}