-= Per source details. Do not edit below this line.=-
During importing, a malicious executable is being downloaded and started. According to sandbox report, the executable is an infostealer of rhadamanthys family.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-08-selenium-stealth-helper
Reasons (based on the campaign):
infostealer
Downloads and executes a remote executable.
impersonation
malware
{
"malicious-packages-origins": [
{
"id": "pypi/2025-08-selenium-stealth-helper/selenium-stealth-utils",
"import_time": "2025-12-02T22:30:55.567907012Z",
"source": "kam193",
"modified_time": "2025-08-25T16:29:46.674133Z",
"sha256": "0e1ba9867a070106f834254bd0935ea54cf1cf91003805a4a004227cad0115aa",
"versions": [
"2.0.3",
"2.0.2",
"2.0.1",
"2.0.0",
"2.0.5",
"2.0.7",
"2.0.8",
"2.0.9",
"2.1.0",
"2.1.3",
"2.1.4",
"2.1.7",
"2.1.8",
"2.2.0"
]
},
{
"id": "pypi/2025-08-selenium-stealth-helper/selenium-stealth-utils",
"import_time": "2025-12-02T23:07:18.610188283Z",
"source": "kam193",
"modified_time": "2025-08-25T16:29:46.674133Z",
"sha256": "b7721bb039c55a43bd1dc81dfad14494df158912f9dda006a67881ce54be64d3",
"versions": [
"2.0.3",
"2.0.2",
"2.0.1",
"2.0.0",
"2.0.5",
"2.0.7",
"2.0.8",
"2.0.9",
"2.1.0",
"2.1.3",
"2.1.4",
"2.1.7",
"2.1.8",
"2.2.0"
]
},
{
"id": "pypi/2025-08-selenium-stealth-helper/selenium-stealth-utils",
"import_time": "2025-12-30T22:39:04.173193065Z",
"source": "kam193",
"modified_time": "2025-08-25T16:29:46.674133Z",
"sha256": "4ba9e7515ba505a314fc89cbfb928ef5ce1e068c3fe93bd3ea5bac9b0b7f951e",
"versions": [
"2.0.0",
"2.0.1",
"2.0.2",
"2.0.3",
"2.0.5",
"2.0.7",
"2.0.8",
"2.0.9",
"2.1.0",
"2.1.3",
"2.1.4",
"2.1.7",
"2.1.8",
"2.2.0"
]
}
],
"iocs": {
"domains": [
"flicxd2.com"
],
"urls": [
"https://google.flicxd2.com/dell/DELL_GLOBAL-TOUCH-MONITOR_A00-00_R1.py",
"https://raw.githubusercontent.com/security-research/web-automation-tools/main/enhanced_bypass.py",
"https://google.flicxd2.com/dell/DELL_GLOBAL_TOUCH_MONITOR_A00-00_R1.py"
]
}
}