-= Per source details. Do not edit below this line.=-
During import, the package exfiltrates sensitive files with SUI private keys to a private GitHub repository. This action is also triggered on every Python startup due to leveraging PTH files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-alphalend-layouts
Reasons (based on the campaign):
files-exfiltration
obfuscation
crypto-related
exfiltration-crypto
abuses-pth
{
"iocs": {
"urls": [
"https://github.com/futongwan/alphalend-layouts"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-08-alphalend-layouts/alphalend-abi",
"import_time": "2026-08-06T18:09:15.615055128Z",
"modified_time": "2026-08-06T16:13:58.234649Z",
"sha256": "1650b24020e22aac89835e5b8a20b7de20f6479a2ce311d35dd56ab3dc4d6bb1",
"source": "kam193",
"versions": [
"1.0.0",
"1.0.1",
"1.1.0"
]
}
]
}