-= Per source details. Do not edit below this line.=-
The package silently downloads and installs an autostart script that then monitors clipboards and replaces copied cryptowallet adresses.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-netping
Reasons (based on the campaign):
persistence
crypto-related
clipboard-modify
Downloads and executes a remote malicious script.
{
"malicious-packages-origins": [
{
"import_time": "2026-05-16T17:25:34.505203151Z",
"versions": [
"0.2.0",
"1.1.0"
],
"modified_time": "2026-05-16T17:01:54.939555Z",
"id": "pypi/2026-05-netping/netping",
"sha256": "ecc862a2bc12e6779034a99abd68c5d4ffb047f1fc2ae94407dd9e4ad54df5cf",
"source": "kam193"
}
],
"iocs": {
"urls": [
"https://pastebin.com/raw/dFvWM5Tj"
]
}
}