-= Per source details. Do not edit below this line.=-
The package, distinguished as a speed testing or typosquatted Telegram library, contains a Telegram bot to perform remote control of the computer
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-10-speedd-testing-bot
Reasons (based on the campaign):
rat
Downloads and executes a remote malicious script.
typosquatting
{
"malicious-packages-origins": [
{
"source": "kam193",
"sha256": "ef643052c84683fba662eaded2786ba6fa993e69224608070ad949d4f3d0c3e4",
"versions": [
"0.3"
],
"import_time": "2026-01-05T01:37:14.431359642Z",
"modified_time": "2026-01-05T01:09:06.719179Z",
"id": "pypi/2025-10-speedd-testing-bot/pyrogrom"
},
{
"source": "kam193",
"sha256": "945378a66519eda82d6f08e634cd3f6bb0b7bf543d662180483b060c792e32f3",
"versions": [
"0.3"
],
"import_time": "2026-01-12T23:35:38.661499433Z",
"modified_time": "2026-01-05T01:09:06.719179Z",
"id": "pypi/2025-10-speedd-testing-bot/pyrogrom"
},
{
"source": "kam193",
"sha256": "b8808614ba04c7728b1266e3b1386174dd49c3505b567b3e44e216af2364c5db",
"versions": [
"0.3"
],
"import_time": "2026-01-18T23:07:34.011634288Z",
"modified_time": "2026-01-05T01:09:06.719179Z",
"id": "pypi/2025-10-speedd-testing-bot/pyrogrom"
},
{
"source": "kam193",
"sha256": "ac1a23aa49923fdd9d7f1a49a5bafed6f9d356a85f052ae1375467ef12d66861",
"versions": [
"0.3"
],
"import_time": "2026-02-26T09:49:02.3312722Z",
"modified_time": "2026-01-05T01:09:06.719179Z",
"id": "pypi/2025-10-speedd-testing-bot/pyrogrom"
}
],
"iocs": {
"urls": [
"https://pastebin.com/raw/xAT1vudj",
"https://i7trak-id3i.onrender.com",
"https://pastebin.com/raw/M3Rh68JJ"
],
"domains": [
"server-unlock-hack.onrender.com"
]
}
}