-= Per source details. Do not edit below this line.=-
During import, the package attempts to exfiltrate sensitive Telegram session files
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-02-hashtools32
Reasons (based on the campaign):
exfiltration-credentials
files-exfiltration
{
"iocs": {
"ips": [
"83.147.255.125"
]
},
"malicious-packages-origins": [
{
"sha256": "689514b83cd6496b0a4213d26325e73cd2c4f0e19128b969d19797bcdd4b131d",
"source": "kam193",
"modified_time": "2026-02-27T19:50:28.642425Z",
"id": "pypi/2026-02-hashtools32/hashtools32",
"import_time": "2026-02-27T20:11:38.237599399Z",
"versions": [
"1.0.0",
"2.1.0"
]
},
{
"sha256": "09c9db1ee500166c34dca9d69cdee7100921741b3ef42a6d96c0ec7ce1f319f7",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:14:31Z",
"id": "RLMA-2026-00378",
"import_time": "2026-03-19T12:18:17.66479611Z",
"versions": [
"2.1.0"
]
}
]
}