-= Per source details. Do not edit below this line.=-
During processing the user requests, the package looks for URLs related to checkouts using services: - credomatic.compassmerchantsolutions.com - checkout.baccredomatic.com and exfiltrates given credit card numbers, verification codes etc. Interestingly, it checks even 3DS responses.
Clone of the legitimate "cloudscraper" package.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-07-cloudscrapersafe
Reasons (based on the campaign):
action-hidden-in-lib-usage
exfiltration-generic
clones-real-package
{
"malicious-packages-origins": [
{
"id": "RLMA-2025-03563",
"import_time": "2025-08-01T10:07:10.358657955Z",
"sha256": "aaa50ce8270e9aea79dd5e82e629190c5453fa565f609771d277746bf84de6e2",
"source": "reversing-labs",
"modified_time": "2025-07-31T19:14:33Z",
"versions": [
"3.0.0",
"3.1.0",
"3.1.1"
]
},
{
"id": "pypi/2025-07-cloudscrapersafe/cloudscrapersafe",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.044692709Z",
"sha256": "6944a90e2050c1774fddbb3e1bc7bac1c298245b9deef45fb50fd828a4050ed5",
"source": "kam193",
"modified_time": "2025-07-06T15:18:55Z"
},
{
"id": "pypi/2025-07-cloudscrapersafe/cloudscrapersafe",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.052906441Z",
"sha256": "2420d6a750823b640af4d97d3a2a26383ce9e32d3ac266e4792675e8beb9b806",
"source": "kam193",
"modified_time": "2025-07-06T15:18:55Z"
},
{
"id": "pypi/2025-07-cloudscrapersafe/cloudscrapersafe",
"import_time": "2025-12-10T21:38:57.343196157Z",
"sha256": "51d27c65c6f9d6dc0bf33a47219228da73ffd60b15808b0bf0b8a4bd027fb16c",
"source": "kam193",
"modified_time": "2025-07-06T15:18:55Z",
"versions": [
"3.0.0",
"3.1.0",
"3.1.1"
]
},
{
"id": "RLUA-2026-00196",
"import_time": "2026-03-19T12:19:33.698411843Z",
"sha256": "8f9df6a19142786919843598f583185471e6b998b404faf0fa7316526da472eb",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:12:26Z"
}
]
}