-= Per source details. Do not edit below this line.=-
Package is prepared to exfiltrate .log and .txt files to the target already associated with exfiltrating sensitive data.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-04-renderctx
Reasons (based on the campaign):
backdoor
files-exfiltration
crypto-related
The malicious code is intentionally included in a dependency of the package
{
"iocs": {
"urls": [
"https://renderkit1.vercel.app",
"https://ctx-graphics.vercel.app"
],
"domains": [
"renderkit1.vercel.app",
"ctx-graphics.vercel.app"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-04-renderctx/funkratov-renderkit",
"import_time": "2026-05-01T14:52:46.375560379Z",
"sha256": "78b5f3b4a8756df49b4a5eb41647e9dd20328da005f95869f81447355e2f7880",
"source": "kam193",
"modified_time": "2026-05-01T14:14:02.795024Z",
"versions": [
"0.1.0"
]
}
]
}