-= Per source details. Do not edit below this line.=-
This package is a clone of Pillow library with malicious code hidden in an image using steganography. The code is the used in a dependant package to install an SSH backdoor.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-textwrap-toolkit-stager
Reasons (based on the campaign):
backdoor
obfuscation
crypto-related
Downloads and executes a remote malicious script.
exfiltration-crypto
{
"malicious-packages-origins": [
{
"sha256": "a6eea31746baa37e55a76fec564eda1852839be005d53ae1e24bf2b9ea4c7875",
"modified_time": "2026-07-21T06:01:48.065059Z",
"versions": [
"1.0.0",
"1.0.2",
"1.0.4"
],
"source": "kam193",
"id": "pypi/2026-06-textwrap-toolkit-stager/rasterkit",
"import_time": "2026-07-21T07:23:25.393717105Z"
}
],
"iocs": {
"urls": [
"http://194.5.152.9:5555/report",
"http://194.5.152.9:8080/hacks/textwrap-toolkit/textwrap_toolkit/__init__.py",
"http://194.5.152.9:5555/tao"
],
"ips": [
"194.5.152.9"
]
}
}