-= Per source details. Do not edit below this line.=-
Package downloads an executable, places it distinguished as a Python binary and starts it. At the time of analysis, the URL was no longer active, so it was not possible to confirm the exact behaviour.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-01-old-terminalbrush
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"versions": [
"0.1",
"0.2.4"
],
"import_time": "2026-01-21T20:11:54.240415641Z",
"sha256": "35e06fb41f9c1a4f082cf49a72dec89fc5b4d2f6580b97e527d291d50807b801",
"source": "kam193",
"id": "pypi/2026-01-old-terminalbrush/terminalbrush",
"modified_time": "2026-01-21T19:31:32.049047Z"
}
],
"iocs": {
"urls": [
"https://free-proxies.cloud/download"
]
}
}