-= Per source details. Do not edit below this line.=-
During import, the package exfiltrates cryptocurrency wallet files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-kotanku
Reasons (based on the campaign):
exfiltration-crypto
uses-telegram-bot
{
"malicious-packages-origins": [
{
"id": "pypi/2026-08-kotanku/kotanku",
"import_time": "2026-08-09T21:13:20.906360042Z",
"sha256": "2281ff1cf735f26084f13f5f3ef5e1d5f9faf8cf06254532e5ee6d27204f52d1",
"versions": [
"0.1.0"
],
"source": "kam193",
"modified_time": "2026-08-09T20:39:54.681731Z"
}
]
}