-= Per source details. Do not edit below this line.=-
Package exfiltrates credentials, env variables and other sensitive data on running. Notably, exfiltrated cloud credentials were immediately checked from a remote location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-12-hellospa
Reasons (based on the campaign):
exfiltration-generic
exfiltration-env-variables
exfiltration-cloud-tokens
exfiltration-credentials
{
"iocs": {
"domains": [
"eoaqkzhr0rddtp6.m.pipedream.net"
]
},
"malicious-packages-origins": [
{
"modified_time": "2025-12-03T10:14:16.454399Z",
"sha256": "276fd70d8b56465c07e6a06281b93ef014fcab93ce00be738e645501713dbdda",
"source": "kam193",
"versions": [
"90.0.0"
],
"id": "pypi/2025-12-hellospa/hellospa",
"import_time": "2025-12-03T11:06:59.664791185Z"
}
]
}