-= Per source details. Do not edit below this line.=-
Package is prepared to exfiltrate .log and .txt files to the target already associated with exfiltrating sensitive data.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-04-renderctx
Reasons (based on the campaign):
backdoor
files-exfiltration
crypto-related
The malicious code is intentionally included in a dependency of the package
{
"malicious-packages-origins": [
{
"id": "pypi/2026-04-renderctx/renderkitcore",
"import_time": "2026-05-01T14:52:46.378949088Z",
"source": "kam193",
"versions": [
"0.1.0"
],
"modified_time": "2026-05-01T14:25:42.894509Z",
"sha256": "a66bf58bff553ec613604164eb60adcb89fcde468491b746838a6e2c18b0e3a0"
}
],
"iocs": {
"urls": [
"https://renderkit1.vercel.app",
"https://ctx-graphics.vercel.app"
],
"domains": [
"renderkit1.vercel.app",
"ctx-graphics.vercel.app"
]
}
}