-= Per source details. Do not edit below this line.=-
Importing the module starts a loop that listens to key strokes and on every capslock press exfiltrates screenshot to a hardcoded location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-04-old-nwin32tls
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"source": "kam193",
"sha256": "72555231efbf126e61cb3aa59d3482bc7967af46898e46eb2b9b7f81af8cd40e",
"import_time": "2026-04-02T20:47:26.853301096Z",
"modified_time": "2026-04-02T20:28:37.671144Z",
"versions": [
"0.0.1"
],
"id": "pypi/2026-04-old-nwin32tls/nwin64tls"
}
]
}