-= Per source details. Do not edit below this line.=-
Starting version 1.0.7, the package contains obfuscated code and embedded binary that is executed during the import, sharing many similarities with package oxntime. The embedded seems to act as a guard for further execution, with some sandbox evasion techniques and time-based actions.
Prior to 1.0.7, the package offered obfuscation techniques.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-oxntime
Reasons (based on the campaign):
obfuscation
The package contains code to detect if it is running in a sandbox environment.
target:android
covering-tracks
{
"malicious-packages-origins": [
{
"import_time": "2026-07-08T14:18:00.375552551Z",
"source": "kam193",
"sha256": "78d60e25c1258021c4fb69a93456c76ef1157be852c7b9dc7165290ca599b0f7",
"versions": [
"1.0.0",
"1.0.1",
"1.0.2",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7"
],
"id": "pypi/2026-07-oxntime/turbod",
"modified_time": "2026-07-08T13:32:30.532978Z"
}
]
}