-= Per source details. Do not edit below this line.=-
Code exfiltrates sensitive crypto wallet's files and sets up a keylogger trying to catch the password to the wallet
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-04-pckg-sv
Reasons (based on the campaign):
crypto-related
keylogger
exfiltration-crypto
persistence
{
"malicious-packages-origins": [
{
"id": "pypi/2026-04-pckg-sv/svchost",
"import_time": "2026-04-14T06:43:48.390562158Z",
"sha256": "a56926028e7e253a1ffb3ba27d6514a5cbc6b23964d7e1094846a895dd322656",
"source": "kam193",
"modified_time": "2026-04-14T05:42:26.252271Z",
"versions": [
"0.1.0"
]
}
]
}