-= Per source details. Do not edit below this line.=-
Obfuscated code is used to abuse systems of garena[.]com for mass account generation, bypassing their security systems.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-neroteam-v1
Reasons (based on the campaign):
obfuscation
abusing-3rd-api
The package contains code to detect if it is running in a sandbox environment.
{
"malicious-packages-origins": [
{
"id": "pypi/2026-07-neroteam-v1/neroteam-v1",
"sha256": "458a2993d1a429a687102ddfca3f9fc0c91f72373b07ccad6ff83fb56add7e58",
"modified_time": "2026-07-20T08:06:19.358107Z",
"import_time": "2026-07-20T09:08:25.327277863Z",
"versions": [
"1.0.0",
"1.0.1",
"1.0.2",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7"
],
"source": "kam193"
}
]
}