-= Per source details. Do not edit below this line.=-
Importing the module, downloads and starts a malicious executable identified as infostealer.
Based on Telegram links, this is related to the 2025-12-synium campaign, but uses slightly different techniques.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-12-runtimeutils
Reasons (based on the campaign):
malware
Downloads and executes a remote executable.
infostealer
{
"malicious-packages-origins": [
{
"import_time": "2025-12-24T23:07:31.45906757Z",
"sha256": "8718f9207ffeca355720b0d4a59cc778fabe7879fc354837d655affac6a82321",
"modified_time": "2025-12-24T22:45:19.363834Z",
"source": "kam193",
"id": "pypi/2025-12-runtimeutils/envtoolsx",
"versions": [
"1.0.0"
]
}
],
"iocs": {
"urls": [
"http://89.39.121.49:20578/Helper.exe"
],
"ips": [
"89.39.121.49"
]
}
}