-= Per source details. Do not edit below this line.=-
Facebook automation/hacking tool, with a part of its code obfuscated. Given that other packages from this uploader exfiltrate user's credentials, this is likely to hide a malicious action.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-03-old-nai
Reasons (based on the campaign):
exfiltration-credentials
abusing-3rd-api
action-hidden-in-lib-usage
{
"iocs": {
"domains": [
"nasweb.000webhostapp.com"
]
},
"malicious-packages-origins": [
{
"versions": [
"1.0"
],
"modified_time": "2026-03-13T10:41:13.34275Z",
"sha256": "09861068d4a40cdebd80dae1ae4db85b45498bdb1f7f039cf44b33f41e68534f",
"id": "pypi/2026-03-old-nai/nfd",
"source": "kam193",
"import_time": "2026-03-13T11:14:45.870602724Z"
}
]
}