-= Per source details. Do not edit below this line.=-
The package contains an embedded malicious executable (probably blank grabber) started when running the module.
Probably continuation of 2025-05-pydoxing
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-05-telegramdoxing
Reasons (based on the campaign):
infostealer
infostealer:blankgrabber
{
"malicious-packages-origins": [
{
"id": "pypi/2025-05-telegramdoxing/telegramdoxing",
"import_time": "2025-12-02T22:30:55.629890141Z",
"modified_time": "2025-05-12T20:59:25Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "c633ea245398c5eee464ce4de052ff892074a3697a2fd03419d82fd3026ffba5",
"source": "kam193"
},
{
"id": "pypi/2025-05-telegramdoxing/telegramdoxing",
"import_time": "2025-12-02T23:07:18.671519413Z",
"modified_time": "2025-05-12T20:59:25Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "4cdffd265ab7e5d199258a068bf6c251370ae931fc905109bd2fb659cd7d9114",
"source": "kam193"
},
{
"id": "pypi/2025-05-telegramdoxing/telegramdoxing",
"import_time": "2025-12-10T21:38:57.858043234Z",
"modified_time": "2025-05-12T20:59:25Z",
"sha256": "c2c1dbf6a62df14bd6ece87af741c302a45dbe41baa397d9e472b2a71b5a58e5",
"source": "kam193",
"versions": [
"0.1.0"
]
}
]
}