-= Per source details. Do not edit below this line.=-
During importing, the package starts a thread that exfiltrates user's files
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-01-icloudprocessor
Reasons (based on the campaign):
{
"iocs": {
"ips": [
"84.21.173.202"
],
"urls": [
"http://84.21.173.202:5000/api/files"
]
},
"malicious-packages-origins": [
{
"modified_time": "2026-01-22T07:31:50.977096Z",
"id": "pypi/2026-01-icloudprocessor/icloudprocessor",
"import_time": "2026-01-22T08:09:59.804955734Z",
"versions": [
"0.1.0",
"1.0.0",
"1.0.1",
"1.0.7",
"1.0.9",
"1.0.10"
],
"sha256": "67b215e1995682b83e1afa8c297ecbdfe93d12db8cc11341b6bda84116d95814",
"source": "kam193"
}
]
}