-= Per source details. Do not edit below this line.=-
The package exfiltrates sensitive files and env variables
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-vfat
Reasons (based on the campaign):
exfiltration-generic
exfiltration-env-variables
exfiltration-credentials
{
"malicious-packages-origins": [
{
"id": "pypi/2026-05-vfat/vfat-ai",
"sha256": "98a606c66789ae1326b7e1802465d1650ef2c691821578936448f403ec421bb0",
"modified_time": "2026-05-19T06:26:42.616857Z",
"versions": [
"0.3.151"
],
"import_time": "2026-05-19T07:48:44.463633443Z",
"source": "kam193"
}
]
}