-= Per source details. Do not edit below this line.=-
Malicious clone of legitimate "license" package. When using the find_by_key function, the malicious code from strongly obfuscated files is loaded. It then at least collects data from cryptowallets and password managers and exfiltrate them to a hardcoded remote location.
Prior version 0.1b2, the malicious code was hosted externally and downloaded when triggered.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-03-license-utils-kit
Reasons (based on the campaign):
infostealer
obfuscation
crypto-related
action-hidden-in-lib-usage
exfiltration-credentials
clones-real-package
{
"iocs": {
"domains": [
"apachelicense.vercel.app"
],
"ips": [
"66.45.225.94"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-03-license-utils-kit/apachelicense",
"import_time": "2026-03-23T20:48:31.567612116Z",
"modified_time": "2026-03-23T20:41:45.460194Z",
"sha256": "9d96d45a87e117e72107d6d6dfbe8c4e94323323bc28ce9accd8ccba39a0a46c",
"source": "kam193",
"versions": [
"0.1a1"
]
},
{
"id": "pypi/2026-03-license-utils-kit/apachelicense",
"import_time": "2026-03-23T21:47:45.570498475Z",
"modified_time": "2026-03-23T20:41:45.460194Z",
"sha256": "8cb3d989a52bed71e3c0c981edf8cf82632c1fc6e3a0ea9c39f812e7967848a7",
"source": "kam193",
"versions": [
"0.1a1"
]
},
{
"id": "pypi/2026-03-license-utils-kit/apachelicense",
"import_time": "2026-03-26T21:44:48.187993542Z",
"modified_time": "2026-03-23T20:41:45.460194Z",
"sha256": "031eef30ab036b21c588c2057db7591f222501d19364223cc502b09d63811c6f",
"source": "kam193",
"versions": [
"0.1a1"
]
},
{
"id": "pypi/2026-03-license-utils-kit/apachelicense",
"import_time": "2026-04-08T20:17:57.404727959Z",
"modified_time": "2026-03-23T20:41:45.460194Z",
"sha256": "9860722a2a2aed103df780cb27b4c599301607ba92d3827a8e7fd1aabcd4fe55",
"source": "kam193",
"versions": [
"0.1a1"
]
}
]
}