-= Per source details. Do not edit below this line.=-
During importing, code starts a malicious script performing exfiltration of sensitive data and credentials from e.g. browsers and Discord clients to a remote location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-03-coreloader
Reasons (based on the campaign):
infostealer
exfiltration-credentials
exfiltration-browser-data
spyware-like
{
"malicious-packages-origins": [
{
"id": "pypi/2026-03-coreloader/coredxloader",
"import_time": "2026-03-31T17:25:25.861817499Z",
"sha256": "b26408ee7735357c61e0a81e60620000999ef84eba419797b20858e5ce5b4a62",
"source": "kam193",
"modified_time": "2026-03-31T17:07:08.653939Z",
"versions": [
"0.1.0",
"0.1.1"
]
}
]
}