-= Per source details. Do not edit below this line.=-
During import, package downloads and executes an obfuscated script. The code then adds a new authorized SSH key and reports back the IP of the current environment. After that, the code also attempts to exfiltrate cryptocurrency wallet data
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-textwrap-toolkit-stager
Reasons (based on the campaign):
backdoor
obfuscation
crypto-related
Downloads and executes a remote malicious script.
exfiltration-crypto
{
"malicious-packages-origins": [
{
"id": "pypi/2026-06-textwrap-toolkit-stager/twrap-toolkit",
"import_time": "2026-06-15T22:45:32.270065771Z",
"source": "kam193",
"versions": [
"1.0.0"
],
"modified_time": "2026-06-15T21:52:02.459513Z",
"sha256": "2308804ebaf25e3528cd82eb53bab024eb80d9944a8b60950ef348d7a5022a22"
}
],
"iocs": {
"ips": [
"194.5.152.9"
],
"urls": [
"http://194.5.152.9:5555/report",
"http://194.5.152.9:8080/hacks/textwrap-toolkit/textwrap_toolkit/__init__.py",
"http://194.5.152.9:5555/tao"
]
}
}