-= Per source details. Do not edit below this line.=-
The package contains encrypted code with infostealers targeting Linux and Android (execution under Termux). The encrypted code collects files, browsers data, text messages and exfiltrates them to a Telegram channel.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-wacve-utils
Reasons (based on the campaign):
files-exfiltration
exfiltration-browser-data
uses-telegram-bot
obfuscation
Downloads and executes a remote malicious script.
infostealer
{
"iocs": {
"urls": [
"https://gist.githubusercontent.com/Darknet-Hacker/7f7e01a86e68403a457c4cd0c2d93f1d/raw/"
]
},
"malicious-packages-origins": [
{
"sha256": "de96a68d25555c9ee1792a22b84307ba3bc68d1e012bd841454dc775986260cb",
"import_time": "2026-08-02T11:04:04.155614993Z",
"versions": [
"1.0.7"
],
"source": "kam193",
"id": "pypi/2026-08-wacve-utils/wacve-utils",
"modified_time": "2026-08-02T10:33:07.923444Z"
},
{
"versions": [
"1.0.7"
],
"import_time": "2026-08-02T11:52:33.616443212Z",
"sha256": "24d4ada91d3bb23e5113caff835c4f285579f06da6ebe4153a456fb2627070f7",
"source": "kam193",
"id": "pypi/2026-08-wacve-utils/wacve-utils",
"modified_time": "2026-08-02T10:33:07.923444Z"
}
]
}