-= Per source details. Do not edit below this line.=-
When using the provided functionality, code silently downloads archives with executables to a location excluded from A scanning, and then executes them. The remote content appears to be a legitimate application manipulated via DLL poisoning to perform malicious actions.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-syntaxlogger
Reasons (based on the campaign):
Downloads and executes a remote executable.
action-hidden-in-lib-usage
malware
{
"iocs": {
"urls": [
"https://github.com/HokageRegard/excrypto/raw/refs/heads/main/photo_5992346016880986941_y.pngsss",
"https://github.com/HokageRegard/excrypto/raw/refs/heads/main/screenshot555.jpgzaza"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-05-syntaxlogger/syntaxlogger",
"import_time": "2026-05-13T20:11:04.544620884Z",
"modified_time": "2026-05-13T19:35:19.553578Z",
"sha256": "ebc8a65895fc09c10b6e6bf23926076ec575582e80e084616e6779b091df947d",
"source": "kam193",
"versions": [
"0.1.0",
"0.1.1",
"0.1.2",
"0.1.3",
"0.1.4"
]
}
]
}