-= Per source details. Do not edit below this line.=-
Code exfiltrates the current python code and/or IPythonshell history
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-05-solana-token
Reasons (based on the campaign):
crypto-related
impersonation
action-hidden-in-lib-usage
exfiltration-crypto
{
"iocs": {
"ips": [
"84.54.44.100",
"89.110.96.251",
"89.110.93.132"
],
"urls": [
"http://84.54.44.100:3000/nodes/register",
"http://89.110.96.251/client",
"http://89.110.93.132/client"
]
},
"malicious-packages-origins": [
{
"id": "RLMA-2025-03035",
"sha256": "b4ea71a58c0e0aef4676e96f0dbaf9086f931b18bba78a51cd12c3dd1163dd85",
"source": "reversing-labs",
"versions": [
"0.1.0"
],
"modified_time": "2025-06-18T10:15:24Z",
"import_time": "2025-06-18T15:06:03.60949962Z"
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"id": "pypi/2025-05-solana-token/solana-live",
"sha256": "a63058822f6e5405170beb5fa7f3d9cc186d5e3cee3f21eb00df9964d76f0baa",
"source": "kam193",
"modified_time": "2025-05-16T10:41:32Z",
"import_time": "2025-12-02T22:30:55.586846929Z"
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"id": "pypi/2025-05-solana-token/solana-live",
"sha256": "edea0605b97d331d0da7af79c24a8875042687bf06aed9192f7cded40da09012",
"source": "kam193",
"modified_time": "2025-05-16T10:41:32Z",
"import_time": "2025-12-02T23:07:18.632535385Z"
},
{
"id": "pypi/2025-05-solana-token/solana-live",
"sha256": "938d825ae74bb06936d50f887bbb5b2f59b69746898a6a6379b94919babb7ecb",
"source": "kam193",
"versions": [
"0.1.0"
],
"modified_time": "2025-05-16T10:41:32Z",
"import_time": "2025-12-10T21:38:57.827029389Z"
}
]
}