-= Per source details. Do not edit below this line.=-
Importing the module downloads a script that then download and run an infected executable
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-12-hugginglega
Reasons (based on the campaign):
Downloads and executes a remote executable.
Downloads and executes a remote malicious script.
dependency-confusion
{
"iocs": {
"urls": [
"http://192.3.209.43/favicon.txt"
],
"ips": [
"192.3.209.43"
]
},
"malicious-packages-origins": [
{
"sha256": "d5d590c6a3be8660ec718d66c7ff87f3fe4032a446572ba5a74553fb1757d9a5",
"source": "reversing-labs",
"import_time": "2025-02-03T18:38:06.884853802Z",
"versions": [
"1.1",
"1.2"
],
"id": "RLMA-2025-00475",
"modified_time": "2025-02-03T17:07:28Z"
},
{
"sha256": "0df3dbc3e25b09132ecba6253cc883619214f298e57c5f9db3932b89fd4bd387",
"source": "kam193",
"import_time": "2025-12-02T22:30:55.263049253Z",
"modified_time": "2024-12-29T19:16:24Z",
"id": "pypi/2024-12-hugginglega/hugginglega",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"sha256": "50647cbe9ac6f4cf09b47c93b53cd292dc5d358f04f0efb1ccd5ba48dd58bc5d",
"source": "kam193",
"import_time": "2025-12-02T23:07:18.287492106Z",
"modified_time": "2024-12-29T19:16:24Z",
"id": "pypi/2024-12-hugginglega/hugginglega",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"sha256": "29b87fe4b9030255c3ad4ef83b4ef42a99467cf800e0a2c8753873994d08ae12",
"source": "kam193",
"import_time": "2025-12-10T21:38:57.538959692Z",
"versions": [
"1.0",
"1.1",
"1.3",
"1.2",
"2.0"
],
"id": "pypi/2024-12-hugginglega/hugginglega",
"modified_time": "2024-12-29T19:16:24Z"
}
]
}