-= Per source details. Do not edit below this line.=-
The package downloads an executable and adds it to autostart. The downloaded application then periodically creates a screenshot and sends it to a Discord channel, as well as waits for further instructions
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-02-dzuseragents
Reasons (based on the campaign):
Downloads and executes a remote executable.
peristence-autorun
spyware-like
{
"iocs": {
"urls": [
"https://dzflavors.com/Event%20Service.exe"
]
},
"malicious-packages-origins": [
{
"import_time": "2026-02-14T12:12:33.983220575Z",
"modified_time": "2026-02-14T11:56:39.712189Z",
"id": "pypi/2026-02-dzuseragents/dzuseragents",
"sha256": "f0be670ad8e17f42129943a744559ebb8818c581bc637c1469cf8553b7b8f8c9",
"source": "kam193",
"versions": [
"0.0.1",
"0.0.2"
]
}
]
}