-= Per source details. Do not edit below this line.=-
Package silently executes in background a remote script. During the analysis, the script was not accessible
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-02-colorss
Reasons (based on the campaign):
typosquatting
Downloads and executes a remote malicious script.
{
"iocs": {
"urls": [
"https://airaproxy.com/api/"
],
"domains": [
"airaproxy.com"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-02-colorss/colorss",
"import_time": "2026-02-01T10:44:20.390721515Z",
"sha256": "de8be235bf17ee738265f4a0254263fc0caeefa1f9228c9f6f122dfd7b2fac2d",
"source": "kam193",
"modified_time": "2026-02-01T10:28:48.127259Z",
"versions": [
"0.1.0"
]
},
{
"id": "pypi/2026-02-colorss/colorss",
"import_time": "2026-02-01T11:08:43.085593049Z",
"sha256": "5183bf5a7f0672f53ec3f08c820475ea4882ccf1b4e48564e804d85783eebf10",
"source": "kam193",
"modified_time": "2026-02-01T10:28:48.127259Z",
"versions": [
"0.1.0"
]
}
]
}