-= Per source details. Do not edit below this line.=-
Malicious clone of a legitimate package "curl-cffi". When importing the module, it runs an obfuscated PowerShell command
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-08-cffi-curl
Reasons (based on the campaign):
typosquatting
obfuscation
malware
clones-real-package
{
"malicious-packages-origins": [
{
"source": "reversing-labs",
"sha256": "b5a05745087bdbd7fd40c331c27dbefcadebdb63972390b2c99d677b42604270",
"versions": [
"0.13.0"
],
"import_time": "2025-09-26T11:05:31.75539764Z",
"modified_time": "2025-09-26T09:13:48Z",
"id": "RLMA-2025-04752"
},
{
"source": "kam193",
"sha256": "1e9ea65819468728fa86fb297e98f30cc327fc8e9b224f90b2847a2d89bf9525",
"versions": [
"0.13.0"
],
"import_time": "2025-12-02T22:30:55.039001664Z",
"modified_time": "2025-08-20T19:19:23.122455Z",
"id": "pypi/2025-08-cffi-curl/cffi-curl"
},
{
"source": "kam193",
"sha256": "1bdc2d55f462ed9009995743e5bc50ed10641cffa24d5b16606e3a479fffae10",
"versions": [
"0.13.0"
],
"import_time": "2025-12-02T23:07:18.047404717Z",
"modified_time": "2025-08-20T19:19:23.122455Z",
"id": "pypi/2025-08-cffi-curl/cffi-curl"
},
{
"source": "reversing-labs",
"sha256": "fbc1c68f5a2291eea2fd6b72cf7a50c7b4c19b3e7797cb7b4d204c5d85d58ad1",
"import_time": "2026-03-19T12:19:32.743170373Z",
"modified_time": "2026-03-18T12:12:18Z",
"id": "RLUA-2026-00183"
}
]
}