-= Per source details. Do not edit below this line.=-
Code hidden in setup.py downloads and executes multi-stage malicious code. Encrypted code from Github downloads a batch script, which then downloads and starts a next executable, which appears to be some kind of infostealer.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-02-novatwo
Reasons (based on the campaign):
Downloads and executes a remote executable.
obfuscation
malware
{
"malicious-packages-origins": [
{
"source": "reversing-labs",
"import_time": "2025-03-03T15:07:16.28237519Z",
"id": "RLMA-2025-01226",
"sha256": "dd747563857fe8c81e8887889a6c0f30af200475e4e92b567c5fdfaea17804f8",
"versions": [
"0.1"
],
"modified_time": "2025-03-03T13:45:04Z"
},
{
"source": "kam193",
"import_time": "2025-12-02T22:30:55.361017014Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "93a018938d538a68516f05db9d598a180fd6126357cf90e0467081bb6f02cd39",
"id": "pypi/2025-02-novatwo/novatwo",
"modified_time": "2025-02-02T22:24:54Z"
},
{
"source": "kam193",
"import_time": "2025-12-02T23:07:18.393250064Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "1af6bb35b7731df522c58205dc15fd6f54a91770353f372a1649e9bb7020dff6",
"id": "pypi/2025-02-novatwo/novatwo",
"modified_time": "2025-02-02T22:24:54Z"
},
{
"source": "kam193",
"import_time": "2025-12-10T21:38:57.613693016Z",
"id": "pypi/2025-02-novatwo/novatwo",
"sha256": "c749128c79b643309443d3eb241700a4c1d8f40e8984d8902814118faea4252a",
"versions": [
"0.1"
],
"modified_time": "2025-02-02T22:24:54Z"
}
],
"iocs": {
"urls": [
"https://raw.githubusercontent.com/sandraajvab/a/refs/heads/main/x.txt",
"https://audacityrecorder.org/suhub",
"https://audacityrecorder.org/donald"
]
}
}