-= Per source details. Do not edit below this line.=-
Importing the module, downloads and starts a malicious executable identified as infostealer.
Based on Telegram links, this is related to the 2025-12-synium campaign, but uses slightly different techniques.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-12-runtimeutils
Reasons (based on the campaign):
malware
Downloads and executes a remote executable.
infostealer
{
"iocs": {
"urls": [
"http://89.39.121.49:20578/Helper.exe"
],
"ips": [
"89.39.121.49"
]
},
"malicious-packages-origins": [
{
"versions": [
"1.0.2",
"1.0.1",
"1.0.0",
"1.0.2"
],
"modified_time": "2025-12-21T14:03:30.5446Z",
"sha256": "4d312906cc585fcd02b2ac0b52bb04a23b0294532e3625c7f5e27bf1e4b51e4a",
"id": "pypi/2025-12-runtimeutils/runtimeutils",
"source": "kam193",
"import_time": "2025-12-21T14:37:49.461805313Z"
},
{
"versions": [
"1.0.2",
"1.0.1",
"1.0.0",
"1.0.2"
],
"modified_time": "2025-12-21T14:03:30.5446Z",
"sha256": "a5da1962c4896546065e477eae3461c641d8cab05d4fdd375f7b26bef6d502fa",
"id": "pypi/2025-12-runtimeutils/runtimeutils",
"source": "kam193",
"import_time": "2025-12-24T23:07:31.460845305Z"
},
{
"versions": [
"1.0.0",
"1.0.1",
"1.0.2",
"1.0.2"
],
"modified_time": "2025-12-21T14:03:30.5446Z",
"sha256": "c0aa179cbb808337b4f5012f05c5a6135a6d0990422dc4b3f8149ab1b0af24a9",
"id": "pypi/2025-12-runtimeutils/runtimeutils",
"source": "kam193",
"import_time": "2025-12-30T22:39:04.16633131Z"
},
{
"versions": [
"1.0.0",
"1.0.1",
"1.0.2"
],
"modified_time": "2025-12-21T14:03:30.5446Z",
"sha256": "fac39c3282cf7700b74a786ebcb009bf685ea520f14fa41a9c30205e551dd20b",
"id": "pypi/2025-12-runtimeutils/runtimeutils",
"source": "kam193",
"import_time": "2026-04-22T21:21:55.45564432Z"
}
]
}