-= Per source details. Do not edit below this line.=-
The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-make-helper
Reasons (based on the campaign):
files-exfiltration
obfuscation
uses-telegram-bot
{
"malicious-packages-origins": [
{
"id": "pypi/2026-07-make-helper/dev-helper-bg",
"sha256": "9466ff28252daa546dc9a75b6b255e94dc6a6409d69197b40b573d05d002d340",
"modified_time": "2026-07-22T10:25:05.295786Z",
"import_time": "2026-07-22T11:17:40.211735141Z",
"versions": [
"0.1.3",
"0.1.4",
"0.1.6",
"0.1.7"
],
"source": "kam193"
}
],
"iocs": {
"domains": [
"key-2qfm.vercel.app"
],
"urls": [
"https://key-2qfm.vercel.app/api/key"
]
}
}