-= Per source details. Do not edit below this line.=-
Code downloads and starts an executable widely recognized as malware, then sends some results to a Telegram webhook.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-10-md5-en
Reasons (based on the campaign):
malware
Downloads and executes a remote executable.
obfuscation
{
"malicious-packages-origins": [
{
"import_time": "2025-12-02T22:30:55.561982951Z",
"modified_time": "2025-10-15T20:25:13.283637Z",
"sha256": "6e6c3a28d0f2ac99c01f0388f125af39014a9ae4b305887ae6375b8cd897a9fd",
"source": "kam193",
"versions": [
"3.0.0",
"2.0.0",
"1.0.0"
],
"id": "pypi/2025-10-md5-en/saintone"
},
{
"import_time": "2025-12-02T23:07:18.60448977Z",
"modified_time": "2025-10-15T20:25:13.283637Z",
"sha256": "d762a42d55901a472c7070197cef989428ecb0140acfe02c72d719d74b430436",
"source": "kam193",
"versions": [
"3.0.0",
"2.0.0",
"1.0.0"
],
"id": "pypi/2025-10-md5-en/saintone"
},
{
"import_time": "2025-12-30T22:39:04.171298743Z",
"modified_time": "2025-10-15T20:25:13.283637Z",
"sha256": "f1ee1d75528bc6874d1e11b0008405d0bfbcf17cf501bcb8bdc1c7502100c71d",
"source": "kam193",
"versions": [
"1.0.0",
"2.0.0",
"3.0.0"
],
"id": "pypi/2025-10-md5-en/saintone"
}
],
"iocs": {
"urls": [
"https://github.com/annawilson121990-lgtm/annaan/raw/refs/heads/main/bashu.exe"
]
}
}