-= Per source details. Do not edit below this line.=-
On importing the module, the code exfiltrates text files, with the focus on configuration files
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-01-icloud-recovery
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"import_time": "2026-01-22T18:10:22.101885262Z",
"versions": [
"0.1.0",
"0.1.1",
"0.1.2",
"0.1.5",
"0.1.6",
"0.2.0"
],
"source": "kam193",
"id": "pypi/2026-01-icloud-recovery/icloud-recovery",
"modified_time": "2026-01-22T17:20:06.841397Z",
"sha256": "3639028f2f9d36c20b55c655b1d71bc053827f4703e7954b12a4ec3da8edd8d2"
}
]
}