-= Per source details. Do not edit below this line.=-
Package attempts to exfiltrate various credential files. In the analyzed version, the exfiltration target was set as localhost suggesting it's not the final code.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-gauth-client
Reasons (based on the campaign):
exfiltration-credentials
impersonation
files-exfiltration
{
"malicious-packages-origins": [
{
"sha256": "ccc67c8452789facd5ba7b991c89a1410dc3058f1c8112c16812e8d004efdf0f",
"source": "kam193",
"modified_time": "2026-05-04T11:30:49.84345Z",
"id": "pypi/2026-05-gauth-client/cloudauth-sdk",
"versions": [
"0.1.0"
],
"import_time": "2026-05-04T12:42:17.429444392Z"
}
]
}