-= Per source details. Do not edit below this line.=-
Using the provided function results in exfiltrating Discord tokens to a hardcoded location
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-02-old-socketxio
Reasons (based on the campaign):
exfiltration-credentials
action-hidden-in-lib-usage
{
"malicious-packages-origins": [
{
"source": "kam193",
"sha256": "0ebdf2a14543a49aa2f1b1fdeb5a713a43da8326a370249ca370d9023283fb31",
"versions": [
"1.5",
"1.6",
"1.7",
"1.8",
"1.9",
"2.0",
"2.1",
"2.2"
],
"import_time": "2026-02-28T11:07:18.088298557Z",
"modified_time": "2026-02-28T10:44:48.494199Z",
"id": "pypi/2026-02-old-socketxio/socketxio"
}
]
}