-= Per source details. Do not edit below this line.=-
The package intentionally uses the malicious binproto package deploying the malware.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-binproto
Reasons (based on the campaign):
obfuscation
Downloads and executes a remote executable.
action-hidden-in-lib-usage
malware
{
"iocs": {
"domains": [
"duketools.vercel.app"
],
"urls": [
"https://duketools.vercel.app/service/assets/fetchBinary"
]
},
"malicious-packages-origins": [
{
"sha256": "74a9da1afe75ec2379c4bade6ac5145c920900e1a1e1173d59b9003061e3fb0f",
"id": "pypi/2026-05-binproto/datapipe-util",
"source": "kam193",
"modified_time": "2026-05-26T14:12:28.864373Z",
"versions": [
"1.7.2",
"1.7.3"
],
"import_time": "2026-05-26T15:07:45.168797938Z"
}
]
}