-= Per source details. Do not edit below this line.=-
During import, the code attempts to exfiltrate to a hardcoded location sensitive data, including private SSH keys, cloud credentials and Windows SAM database.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-03-polymarkets-sdk
Reasons (based on the campaign):
exfiltration-credentials
files-exfiltration
exfiltration-cloud-tokens
{
"iocs": {
"ips": [
"52.16.41.151"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-03-polymarkets-sdk/polymarkets-sdk",
"import_time": "2026-04-01T15:34:17.768474139Z",
"sha256": "facfcba74011619f5bb2eaf096e41239f81520cb4effff3b45f8b42c84d42060",
"source": "kam193",
"modified_time": "2026-04-01T15:30:14.120234Z",
"versions": [
"1.0.0",
"1.0.1"
]
},
{
"id": "pypi/2026-03-polymarkets-sdk/polymarkets-sdk",
"import_time": "2026-04-01T16:25:43.525317742Z",
"sha256": "b41c34e997e591fca5ebc478ed1464d71d29fe2d2b3b276bcb56b09ff9124791",
"source": "kam193",
"modified_time": "2026-04-01T15:37:06.608356Z",
"versions": [
"1.0.0",
"1.0.1"
]
}
]
}