-= Per source details. Do not edit below this line.=-
Clones of a legitimate library with injected code downloading and executing a malicious executable on import. Dynamic analysis identified it as salatstealer.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-reguestsc
Reasons (based on the campaign):
typosquatting
Downloads and executes a remote executable.
malware
clones-real-package
spyware-like
infostealer
{
"iocs": {
"urls": [
"http://31.76.101.19:8080/Group.exe"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-07-reguestsc/reguestsc",
"import_time": "2026-07-31T09:08:46.954679281Z",
"modified_time": "2026-07-31T09:00:58.821452Z",
"sha256": "20e4ae2ce79408a65e9b4bb348c2d69e20eb6072e3641531e2ec5773f1bbddd6",
"source": "kam193",
"versions": [
"2.34.2"
]
}
]
}