-= Per source details. Do not edit below this line.=-
During import package exfiltrates the environment variables and cloud credentials/tokens to a hardcoded location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-04-sf-th-requests
Reasons (based on the campaign):
exfiltration-env-variables
exfiltration-cloud-tokens
exfiltration-credentials
{
"iocs": {
"ips": [
"100.31.118.36",
"35.170.72.247"
],
"urls": [
"http://100.31.118.36:80/beacon",
"http://35.170.72.247:80/beacon"
]
},
"malicious-packages-origins": [
{
"import_time": "2026-05-03T09:55:46.850049264Z",
"versions": [
"0.2.0"
],
"source": "kam193",
"id": "pypi/2026-04-sf-th-requests/sf-vmeval-requests",
"modified_time": "2026-05-03T08:45:43.946857Z",
"sha256": "a8fa27c8dc6bf13a4f5d92f14414a4f5efc08c1df7f33591a010b4f824e84bc1"
}
]
}