-= Per source details. Do not edit below this line.=-
Typosquatting package that automatically exfiltrates files to a Telegram channel on importing.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-pycryptcore
Reasons (based on the campaign):
typosquatting
files-exfiltration
{
"malicious-packages-origins": [
{
"id": "pypi/2026-05-pycryptcore/pycryptcore",
"import_time": "2026-05-01T12:51:54.517437783Z",
"modified_time": "2026-05-01T12:17:23.403886Z",
"sha256": "3337f9433143a04e30ce5881c7786f787cc882c983ed5e68b22f60fd79f2a0dd",
"source": "kam193",
"versions": [
"0.1.0",
"0.1.1",
"0.1.5",
"0.2.5"
]
}
]
}