-= Per source details. Do not edit below this line.=-
Importing starts an infostealer
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-07-cryptoo
Reasons (based on the campaign):
obfuscation
infostealer
exfiltration-browser-data
exfiltration-generic
crypto-related
exfiltration-crypto
{
"malicious-packages-origins": [
{
"id": "RLMA-2025-03579",
"import_time": "2025-08-01T10:07:10.694650349Z",
"sha256": "daa37d9c03e4135ee4771a0803db1599f5dcefde3e2e97bf8aeaf29887e958ff",
"source": "reversing-labs",
"modified_time": "2025-07-31T19:14:47Z",
"versions": [
"1.6.0",
"2.6.0",
"2.6.2"
]
},
{
"id": "pypi/2025-07-cryptoo/cryptob",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.081583974Z",
"sha256": "b3d2efbd11d3b9495b523b15a2dced4a56a33732c7519c48fe598bda080fece4",
"source": "kam193",
"modified_time": "2025-07-09T14:22:18.396544Z"
},
{
"id": "pypi/2025-07-cryptoo/cryptob",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.091724106Z",
"sha256": "d0ee1f01fb1d9fe3ac1d88bec06c858d0c3e33f2531e7ca1afb30177f0b85e84",
"source": "kam193",
"modified_time": "2025-07-09T14:22:18.396544Z"
},
{
"id": "pypi/2025-07-cryptoo/cryptob",
"import_time": "2025-12-10T21:38:57.384692576Z",
"sha256": "d9fe5e76f4529be2bfc93433e93313c9cf8bab61c9ad4f262eb7f80d759859e0",
"source": "kam193",
"modified_time": "2025-07-09T14:22:18.396544Z",
"versions": [
"1.6.0",
"2.6.0",
"2.6.2"
]
},
{
"id": "RLUA-2026-00236",
"import_time": "2026-03-19T12:19:37.194721344Z",
"sha256": "ce40fa50958b027c334c10e9918f5f2273ca48445e7aac8c205754e38e67b59f",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:12:57Z"
}
]
}