-= Per source details. Do not edit below this line.=-
This package does not carry any malicious payload yet, but uses exactly the same technique as other packages from the campaign aiming to mislead LLM security tools.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-openaii
Reasons (based on the campaign):
Downloads and executes a remote malicious script.
obfuscation
abuses-pth
cryptominer
infostealer
exfiltration-credentials
files-exfiltration
exfiltration-ssh-keys
persistence
typosquatting
covering-tracks
{
"iocs": {
"ips": [
"167.86.108.190"
],
"urls": [
"http://167.86.108.190:7788/stage1.py",
"http://167.86.108.190:7788/.lurves-agent.py"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-09-openaii/chroma-client",
"import_time": "2026-09-13T17:14:18.669535886Z",
"modified_time": "2026-09-13T16:12:34.814684Z",
"sha256": "f74658ebb12f3a5cbf8577a768965f3ae81fbe8a156acc843ecffe3dfe2e5153",
"source": "kam193",
"versions": [
"0.5.7"
]
}
]
}