-= Per source details. Do not edit below this line.=-
During installation package downloads and runs a malicious executable. Likely continuation of 2026-03-rowrap.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-03-roboat-addition
Reasons (based on the campaign):
malware
Downloads and executes a remote executable.
The package overrides the install command in setup.py to execute malicious code during installation.
clones-real-package
{
"malicious-packages-origins": [
{
"modified_time": "2026-03-28T20:17:03.330688Z",
"versions": [
"0.0.1"
],
"id": "pypi/2026-03-roboat-addition/roboats-addition",
"import_time": "2026-03-28T20:45:52.98810883Z",
"source": "kam193",
"sha256": "c446675e15c1160894fe9539d482b3ce2b6e5f85d5038af568bea3169412255f"
},
{
"modified_time": "2026-03-28T20:17:03.330688Z",
"versions": [
"0.0.1"
],
"id": "pypi/2026-03-roboat-addition/roboats-addition",
"import_time": "2026-03-29T12:49:09.561274138Z",
"source": "kam193",
"sha256": "b81399ecdba3bdbae5604132662aa9cb72328e2e79983d30230da811b879ad44"
},
{
"modified_time": "2026-03-28T20:17:03.330688Z",
"versions": [
"0.0.1"
],
"id": "pypi/2026-03-roboat-addition/roboats-addition",
"import_time": "2026-03-29T20:46:34.589018245Z",
"source": "kam193",
"sha256": "6e8cf74cb58e14cc9aa948bbb3b77ee15091d570d18cb595d628464d226925e0"
}
],
"iocs": {
"urls": [
"https://jolly-violet-def9.staraledreamer.workers.dev/DDDD.exe"
],
"domains": [
"jolly-violet-def9.staraledreamer.workers.dev"
]
}
}