-= Per source details. Do not edit below this line.=-
When used, package exfiltrates sensitive environmental variable.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-04-renderctx
Reasons (based on the campaign):
backdoor
files-exfiltration
crypto-related
The malicious code is intentionally included in a dependency of the package
{
"iocs": {
"domains": [
"renderkit1.vercel.app",
"ctx-graphics.vercel.app"
],
"urls": [
"https://renderkit1.vercel.app",
"https://ctx-graphics.vercel.app"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-04-renderctx/chalk-fancy",
"import_time": "2026-05-01T14:29:30.463743137Z",
"modified_time": "2026-05-01T13:46:20.759076Z",
"sha256": "b86a641eb2b6239d8a88849df88a1a148fa5380e3c8767dc59915edb295ef5b3",
"source": "kam193",
"versions": [
"0.0.0",
"0.0.3",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7",
"1.0.8",
"1.0.9"
]
}
]
}