-= Per source details. Do not edit below this line.=-
Using the function simulates some behavior, but then download and runs an Infostealer
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-06-bulktweetbyref
Reasons (based on the campaign):
Downloads and executes a remote executable.
malware
infostealer
{
"malicious-packages-origins": [
{
"modified_time": "2025-07-31T19:14:27Z",
"versions": [
"0.1.0"
],
"sha256": "cc17a758efb55184f78eaea608bb6c116129e75817337ec22401cdb5866f9b09",
"id": "RLMA-2025-03555",
"source": "reversing-labs",
"import_time": "2025-08-01T10:07:10.117556007Z"
},
{
"modified_time": "2025-06-18T05:42:14Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "37f9a6adf2f6bceb8d49b86e00e8fd1d6303e73370f5d9620bfe678dd12525df",
"id": "pypi/2025-06-bulktweetbyref/bulktweetbyref",
"source": "kam193",
"import_time": "2025-12-02T22:30:55.021315068Z"
},
{
"modified_time": "2025-06-18T05:42:14Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "b6e44fa722cba73a0757878305b8641ff0539e6c32ffff20b9484ce39ce6a1aa",
"id": "pypi/2025-06-bulktweetbyref/bulktweetbyref",
"source": "kam193",
"import_time": "2025-12-02T23:07:18.038459587Z"
},
{
"modified_time": "2025-06-18T05:42:14Z",
"versions": [
"0.1.0"
],
"sha256": "d00b2c8787d63545a7825835db960ce79bb2e2b2c952323eeb2d8e292d4977e1",
"id": "pypi/2025-06-bulktweetbyref/bulktweetbyref",
"source": "kam193",
"import_time": "2025-12-10T21:38:57.330820928Z"
},
{
"modified_time": "2026-03-18T12:12:05Z",
"sha256": "b71f763feda620fb8a04ef988df6ca000b618e0187de9b2aa2989069c0ed33c2",
"id": "RLUA-2026-00161",
"source": "reversing-labs",
"import_time": "2026-03-19T12:19:30.923777666Z"
}
],
"iocs": {
"urls": [
"https://github.com/kokochatgpcod/akaak/releases/download/nothinfgg/allinone.exe"
]
}
}