-= Per source details. Do not edit below this line.=-
This package is prepared for silent execution of a malicious executable, with disabling AV protection. While there is no link to the malicious binary inside, the package shares clear indicators of being part of the 2025-11-discord-selfsbotsx campaign.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-11-discord-selfsbotsx
Reasons (based on the campaign):
Downloads and executes a remote executable.
infostealer
malware
peristence-autorun
{
"iocs": {
"urls": [
"https://pastebin.com/raw/HvFhs7zk",
"http://212.80.7.213:20578"
],
"ips": [
"212.80.7.213"
]
},
"malicious-packages-origins": [
{
"modified_time": "2025-12-02T21:29:42.962364Z",
"sha256": "5a6f1f7e308990c5a418b218c6a0cd099913b244d8a5d6fb3aca59dbfc1cd1c1",
"source": "kam193",
"versions": [
"1.0.0"
],
"id": "pypi/2025-11-discord-selfsbotsx/pulsecord",
"import_time": "2025-12-02T22:30:55.450072223Z"
},
{
"modified_time": "2025-12-02T21:29:42.962364Z",
"sha256": "025d4e33a2037fb9ad36cb4b08b122e4439bb4932b73ac6c6f403609e7e1c09e",
"source": "kam193",
"versions": [
"1.0.0"
],
"id": "pypi/2025-11-discord-selfsbotsx/pulsecord",
"import_time": "2025-12-02T23:07:18.473115182Z"
}
]
}