-= Per source details. Do not edit below this line.=-
The package contains code to download and run a malicious executable. The executable contains a remote access trojan controlled via Telegram bot, with capabilities like a keylogger, screen recording, command execution. It also attempts to gain persistence via startup registry keys.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-fastercode
Reasons (based on the campaign):
Downloads and executes a remote executable.
peristence-autorun
uses-telegram-bot
keylogger
rat
spyware-like
{
"malicious-packages-origins": [
{
"sha256": "9dd11cd3c57bf0f46158fd84d7243184d4bd5780e17f49d90f1721e6d0a8f8a1",
"source": "kam193",
"modified_time": "2026-06-19T11:38:53.833167Z",
"versions": [
"1.0.0"
],
"id": "pypi/2026-06-fastercode/fastercoding",
"import_time": "2026-06-19T12:48:22.554562569Z"
}
],
"iocs": {
"urls": [
"https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe"
]
}
}