-= Per source details. Do not edit below this line.=-
Package is disguised as a utility, but in fact loads encrypted code as modules. However, loading it requires knowing the decryption key which is not included in the package.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-ggfmttygl
Reasons (based on the campaign):
obfuscation
The malicious code is intentionally included in a dependency of the package
{
"malicious-packages-origins": [
{
"id": "pypi/2026-05-ggfmttygl/ggfmttygl",
"sha256": "e741cc1df48cc526ad3a27ac702f5dea403723557b4a485f84847340310d66e5",
"import_time": "2026-05-09T17:48:53.537018357Z",
"source": "kam193",
"modified_time": "2026-05-09T17:29:06.065095Z",
"versions": [
"1.0.0"
]
}
]
}