-= Per source details. Do not edit below this line.=-
Obfuscated downloader of encrypted code, compiled to native binary. The remote URL has to be provided to the binary. Likely impersonates legitimate npm library
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-02-qwery-core
Reasons (based on the campaign):
obfuscation
Downloads and executes a remote malicious script.
impersonation
{
"iocs": {
"urls": [
"https://t.me/NexLangPy"
]
},
"malicious-packages-origins": [
{
"source": "kam193",
"import_time": "2026-03-03T20:12:03.92399377Z",
"sha256": "c4861116d64db41be8bae04818ecc9f3542fe4bc30055d57588f6f23c11149f3",
"id": "pypi/2026-02-qwery-core/qwery-core",
"modified_time": "2026-03-03T19:19:13.730225Z",
"versions": [
"1.0.0",
"1.0.1",
"1.0.2",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7"
]
}
]
}