-= Per source details. Do not edit below this line.=-
The package contains code to download and run a malicious executable. The executable contains a remote access trojan controlled via Telegram bot, with capabilities like a keylogger, screen recording, command execution. It also attempts to gain persistence via startup registry keys.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-fastercode
Reasons (based on the campaign):
Downloads and executes a remote executable.
peristence-autorun
uses-telegram-bot
keylogger
rat
spyware-like
{
"malicious-packages-origins": [
{
"sha256": "1c2793304d30de27278e36f79685e9ca60f9f839d7a27d2ea39d8d22e36a8584",
"source": "kam193",
"modified_time": "2026-06-19T10:38:48.958095Z",
"versions": [
"0.1.0",
"0.1.1",
"1.0.0"
],
"id": "pypi/2026-06-fastercode/fastercode",
"import_time": "2026-06-19T11:04:11.922514289Z"
}
],
"iocs": {
"urls": [
"https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe"
]
}
}