-= Per source details. Do not edit below this line.=-
Importing the module starts a loop that listens to key strokes and on every capslock press exfiltrates screenshot to a hardcoded location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-04-old-nwin32tls
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"versions": [
"0.0.1",
"0.0.2",
"0.0.3",
"0.0.5",
"0.0.6",
"0.0.7"
],
"source": "kam193",
"import_time": "2026-04-02T20:47:26.849020058Z",
"modified_time": "2026-04-02T20:26:19.105445Z",
"id": "pypi/2026-04-old-nwin32tls/nwin32tls",
"sha256": "a47778618cad57dbc584afdff7ed138032b69c423a9812e1bc8f86c13129f01d"
}
]
}