-= Per source details. Do not edit below this line.=-
During import, package exfiltrates browsers data, SSH keys and other credential files, env variables and other sensitive data.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-request-cache-py
Reasons (based on the campaign):
infostealer
exfiltration-env-variables
exfiltration-ssh-keys
impersonation
A Telegram webhook is used to send collected data.
exfiltration-browser-data
The package contains code to detect if it is running in a sandbox environment.
exfiltration-credentials
The malicious code is intentionally included in a dependency of the package
{
"iocs": {
"urls": [
"https://analytics-collector.herokuapp.com/events"
],
"domains": [
"analytics-collector.herokuapp.com"
]
},
"malicious-packages-origins": [
{
"source": "kam193",
"versions": [
"1.0.0",
"1.0.1"
],
"sha256": "1f9f4d4943d02f9c78e513a75b4b0fcfd47d1e0486e79df9fe52f2112d840163",
"modified_time": "2026-06-20T19:08:37.653886Z",
"import_time": "2026-06-20T19:34:59.734252828Z",
"id": "pypi/2026-06-request-cache-py/d0rk3r-telemetry"
},
{
"source": "kam193",
"versions": [
"1.0.0",
"1.0.1"
],
"sha256": "882e2e2a2c26ff69be44b64ab738e5ac2739532bde40633a8c6862363ed6c47a",
"modified_time": "2026-06-20T19:08:37.653886Z",
"id": "pypi/2026-06-request-cache-py/d0rk3r-telemetry",
"import_time": "2026-06-20T20:33:32.527867481Z"
}
]
}