-= Per source details. Do not edit below this line.=-
During import, the code uses steganography to extract code from an image hidden in the dependency. The code then adds a new authorized SSH key and reports back the IP of the current environment.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-textwrap-toolkit-stager
Reasons (based on the campaign):
backdoor
obfuscation
crypto-related
Downloads and executes a remote malicious script.
exfiltration-crypto
{
"iocs": {
"ips": [
"194.5.152.9"
],
"urls": [
"http://194.5.152.9:5555/report",
"http://194.5.152.9:8080/hacks/textwrap-toolkit/textwrap_toolkit/__init__.py",
"http://194.5.152.9:5555/tao"
]
},
"malicious-packages-origins": [
{
"modified_time": "2026-07-21T05:46:23.232192Z",
"id": "pypi/2026-06-textwrap-toolkit-stager/rasterkit-demo",
"versions": [
"0.1.0"
],
"source": "kam193",
"sha256": "29eb6057bbc11a0f0180a030db952f9ec8aa39ce8c4b0d437046b20301f5b21a",
"import_time": "2026-07-21T07:23:25.392919797Z"
}
]
}