-= Per source details. Do not edit below this line.=-
During import, package exfiltrates specific global variables to a remote target in a way typical for infostealers
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-12-synium
Reasons (based on the campaign):
exfiltration-credentials
exfiltration-generic
{
"iocs": {
"urls": [
"https://t.me/+nnBhXKORtb8xYzNi"
]
},
"malicious-packages-origins": [
{
"sha256": "85fc917c33d970cb3365ff112f788b229638b757c32eaf99ba1054c8596298c1",
"modified_time": "2025-12-10T18:29:17.889655Z",
"import_time": "2025-12-10T19:36:28.621626956Z",
"source": "kam193",
"versions": [
"1.0.2",
"1.0.1",
"1.0.0"
],
"id": "pypi/2025-12-synium/synium"
}
]
}