MALICIOUS (1) campaign cataloged at 2025-03-23(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2025-03-yolov8mini¶
On importing the module, there is an automated start of a Telegram bot capable of exfiltrating passwords from browsers, executing arbitrary commands and so on. While the description states it's a monitoring tool, the automated start, capabilities targeting secret values suggest malicious intentions.
Abuse categories¶
dependency-confusion
Campaign uses dependency-confusion.
exfiltration_browser_data
Campaign uses exfiltration_browser_data.
exfiltration_generic
Campaign uses exfiltration_generic.
infostealer
Campaign uses infostealer.
remote_commands
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.