-= Per source details. Do not edit below this line.=-
During initialization of the archive-support class, the package starts code from another file and downloads multi-stage malware
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-11-uzip
Reasons (based on the campaign):
Downloads and executes a remote executable.
obfuscation
malware
{
"iocs": {
"ips": [
"77.105.161.164",
"87.120.107.132"
],
"urls": [
"http://77.105.161.164:3301/library",
"http://77.105.161.164:3301/die1",
"http://87.120.107.132:1488/df"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2025-11-uzip/extrazip",
"import_time": "2025-12-27T10:07:20.904674969Z",
"modified_time": "2025-12-27T09:41:01.544951Z",
"sha256": "f58777710463b043a0724ad1d7999807501b56667a10eced314fd036e9303fdf",
"source": "kam193",
"versions": [
"0.1.0"
]
},
{
"id": "pypi/2025-11-uzip/extrazip",
"import_time": "2026-02-26T09:49:02.308071735Z",
"modified_time": "2025-12-27T09:41:01.544951Z",
"sha256": "9aa3db32c22351c4dfcbfdfce89fb38ca19fac546dba3f82d084212f8c830632",
"source": "kam193",
"versions": [
"0.1.0"
]
}
]
}