-= Per source details. Do not edit below this line.=-
The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-make-helper
Reasons (based on the campaign):
files-exfiltration
obfuscation
uses-telegram-bot
{
"iocs": {
"domains": [
"key-2qfm.vercel.app"
],
"urls": [
"https://key-2qfm.vercel.app/api/key"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-07-make-helper/make-helper",
"sha256": "39bf40d5056dc821bcedf5fcc304e26d9e6566f5beb508b6a01874b49d32becd",
"import_time": "2026-07-22T10:21:29.652354006Z",
"modified_time": "2026-07-22T09:26:25.968438Z",
"versions": [
"0.1.0",
"0.1.1"
],
"source": "kam193"
}
]
}