-= Per source details. Do not edit below this line.=-
Installing the package starts a heavily obfuscated Powershell Script that attempts to (at least) overwrite copied crypto wallets
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-03-pythonhttp
Reasons (based on the campaign):
The package overrides the install command in setup.py to execute malicious code during installation.
obfuscation
malware
crypto-related
{
"malicious-packages-origins": [
{
"source": "reversing-labs",
"id": "RLMA-2025-01992",
"modified_time": "2025-03-28T13:06:08Z",
"sha256": "6a122a77250072d59a6c30b2481a19b1b841182f8531a7007131dd824324c4b1",
"versions": [
"0.1",
"1.0.4"
],
"import_time": "2025-03-31T07:07:06.549163703Z"
},
{
"source": "kam193",
"id": "pypi/2025-03-pythonhttp/pythonhttp",
"modified_time": "2025-03-04T10:02:05Z",
"sha256": "47baf933e5681e0c9ccded4eb43838eba6471b269f6d6931be73a7ad98d38974",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.497664702Z"
},
{
"source": "kam193",
"id": "pypi/2025-03-pythonhttp/pythonhttp",
"modified_time": "2025-03-04T10:02:05Z",
"sha256": "3ed5759c2260c5467724f053f3d59eac62f5491fc2d03350fef0a6f832652e3b",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.522521497Z"
},
{
"source": "kam193",
"id": "pypi/2025-03-pythonhttp/pythonhttp",
"modified_time": "2025-03-04T10:02:05Z",
"sha256": "9f890dd2f7a693f0c2fe632b76bd7d111480dab1a6200c6671731ce0b5161f07",
"versions": [
"1.0.4"
],
"import_time": "2025-12-10T21:38:57.740957417Z"
},
{
"source": "reversing-labs",
"id": "RLUA-2026-00669",
"modified_time": "2026-03-18T12:17:50Z",
"sha256": "6415283ba4a5019ab461dcae2e7ff6642ce84db38b6ee5f259c73dd3bdfcf597",
"import_time": "2026-03-19T12:20:18.889986628Z"
}
]
}