-= Per source details. Do not edit below this line.=-
The package exfiltrates Discord tokens to a hardcoded location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-04-old-stringhelp
Reasons (based on the campaign):
exfiltration-credentials
action-hidden-in-lib-usage
{
"malicious-packages-origins": [
{
"source": "kam193",
"id": "pypi/2026-04-old-stringhelp/stringhelp",
"modified_time": "2026-04-18T09:10:50.407831Z",
"sha256": "614fb208fe0dce0e336281a07696b97a699937b1cb5d6167e6d126e8693b7ae6",
"versions": [
"7.0",
"8.0"
],
"import_time": "2026-04-18T09:48:57.438473376Z"
}
]
}