-= Per source details. Do not edit below this line.=-
Importing starts an infostealer
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-07-cryptoo
Reasons (based on the campaign):
obfuscation
infostealer
exfiltration-browser-data
exfiltration-generic
crypto-related
exfiltration-crypto
{
"malicious-packages-origins": [
{
"sha256": "3db10294feb27bde48ccda97d08d509de76d9547950cdabe7f06452cbe33fecd",
"modified_time": "2025-07-31T19:14:48Z",
"id": "RLMA-2025-03580",
"versions": [
"2.8.2"
],
"import_time": "2025-08-01T10:07:10.735035017Z",
"source": "reversing-labs"
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2025-07-09T14:20:53.24019Z",
"id": "pypi/2025-07-cryptoo/cryptoo",
"sha256": "5e5e271a48e340c3f1ca8cd43f8d662a1738236fc5311a4f9adcf0e834976adf",
"import_time": "2025-12-02T22:30:55.083243475Z",
"source": "kam193"
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2025-07-09T14:20:53.24019Z",
"id": "pypi/2025-07-cryptoo/cryptoo",
"sha256": "f63e4b5c515be094f240f956e15464da0258bdd6948006f25419be60138b4764",
"import_time": "2025-12-02T23:07:18.09391685Z",
"source": "kam193"
},
{
"sha256": "f6697b0a706b10ed7b9ac095cc153a05167f43c1fdd88124e61f44e1cb720947",
"modified_time": "2025-07-09T14:20:53.24019Z",
"id": "pypi/2025-07-cryptoo/cryptoo",
"versions": [
"2.8.2"
],
"import_time": "2025-12-10T21:38:57.386525212Z",
"source": "kam193"
},
{
"sha256": "5ac20803a67fbb7e79fc9c7e013444e29912f2ace8b8078fe5f68d424d981df1",
"modified_time": "2026-03-18T12:12:58Z",
"id": "RLUA-2026-00238",
"import_time": "2026-03-19T12:19:37.393733494Z",
"source": "reversing-labs"
}
]
}