-= Per source details. Do not edit below this line.=-
Importing the module exfiltrates content of /var/www/html to a remote host
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-12-system-health-check-test-unique
Reasons (based on the campaign):
files-exfiltration
obfuscation
{
"malicious-packages-origins": [
{
"modified_time": "2025-12-19T20:55:40.603841Z",
"source": "kam193",
"import_time": "2025-12-19T21:36:24.705411469Z",
"id": "pypi/2025-12-system-health-check-test-unique/system-health-check-test-unique",
"versions": [
"0.3.6",
"0.3.5",
"0.3.4",
"0.3.3",
"0.3.2",
"0.3.1",
"0.3.0",
"0.2.9",
"0.2.8",
"0.2.7",
"0.2.6",
"0.1.6",
"0.1.5",
"0.3.6",
"0.3.5",
"0.3.4"
],
"sha256": "10bfd6e986187675dd7d7e3a8f860807e408fd6a91694ca0e0128be83fa8fc47"
},
{
"modified_time": "2025-12-19T20:55:40.603841Z",
"source": "kam193",
"import_time": "2025-12-30T22:39:04.192217834Z",
"id": "pypi/2025-12-system-health-check-test-unique/system-health-check-test-unique",
"versions": [
"0.1.5",
"0.1.6",
"0.2.6",
"0.2.7",
"0.2.8",
"0.2.9",
"0.3.0",
"0.3.1",
"0.3.2",
"0.3.3",
"0.3.4",
"0.3.4",
"0.3.5",
"0.3.5",
"0.3.6",
"0.3.6"
],
"sha256": "5ea3f538083de70d12dc155af48cf0a23c0ed2803cac97b5dbf093265a71558d"
},
{
"modified_time": "2025-12-19T20:55:40.603841Z",
"source": "kam193",
"import_time": "2026-04-22T21:21:55.458268524Z",
"id": "pypi/2025-12-system-health-check-test-unique/system-health-check-test-unique",
"versions": [
"0.1.5",
"0.1.6",
"0.2.6",
"0.2.7",
"0.2.8",
"0.2.9",
"0.3.0",
"0.3.1",
"0.3.2",
"0.3.3",
"0.3.4",
"0.3.5",
"0.3.6"
],
"sha256": "439ce225263440aa80bc75e3ae0bbf2b290e849a05368cc8eb0bfcd380c7177a"
}
],
"iocs": {
"ips": [
"185.208.172.174"
],
"domains": [
"dool.cloudyhost.org",
"cloudyhost.org"
],
"urls": [
"http://dool.cloudyhost.org/up.php"
]
}
}