-= Per source details. Do not edit below this line.=-
During import, the code starts a keylogger and exfiltrates data from cryptowallets.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-random-ua-generator
Reasons (based on the campaign):
keylogger
exfiltration-crypto
{
"iocs": {
"urls": [
"http://157.254.194.47:5000/keylogger",
"http://157.254.194.47:5000/wallets"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-07-random-ua-generator/random-ua-generator",
"sha256": "543206058a0b8e85c8227a0bfdd4752fc61779b24968a0bd5d50ae6b3040387b",
"modified_time": "2026-07-26T19:36:57.32407Z",
"import_time": "2026-07-26T20:26:43.666705485Z",
"versions": [
"0.0.1"
],
"source": "kam193"
}
]
}