-= Per source details. Do not edit below this line.=-
Package is designed to download and execute a remote script, which then downloads and runs a malicious executable
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-12-pdatainstaller
Reasons (based on the campaign):
Downloads and executes a remote malicious script.
malware
Downloads and executes a remote executable.
{
"iocs": {
"urls": [
"https://pastebin.com/raw/s5WB7EtG",
"https://pastebin.com/raw/c3uYVYbT",
"https://github.com/uunnkknnoowwnn/dang/raw/refs/heads/main/svchost.exe",
"https://github.com/yoseffalrg-droid/Reall/raw/refs/heads/main/svchost.exe"
]
},
"malicious-packages-origins": [
{
"import_time": "2026-01-07T20:40:53.377048426Z",
"versions": [
"1.0.0"
],
"source": "kam193",
"id": "pypi/2025-12-pdatainstaller/lnatainstaller",
"modified_time": "2026-01-07T19:46:19.565851Z",
"sha256": "a613dbd371593bf6bcb7ae528a4d7d7dba2fedfc6670c8cb493bb5cbee18f734"
},
{
"import_time": "2026-01-14T21:39:18.45087869Z",
"versions": [
"1.0.0"
],
"source": "kam193",
"id": "pypi/2025-12-pdatainstaller/lnatainstaller",
"modified_time": "2026-01-07T19:46:19.565851Z",
"sha256": "c3822afcab6a1539e1e4fe60243150c1844db475f93311255d63b90c9c8227df"
},
{
"import_time": "2026-01-19T07:14:29.761135598Z",
"versions": [
"1.0.0"
],
"source": "kam193",
"id": "pypi/2025-12-pdatainstaller/lnatainstaller",
"modified_time": "2026-01-07T19:46:19.565851Z",
"sha256": "ae050d9062f7f90317c47faea3b14f97ed56d7f427bb69e884f576714abf5e37"
}
]
}