Skip to content

MALICIOUS (1) campaign cataloged at 2025-06-22(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2025-06-hashidf

If ran as a module, the package silently starts a binary hidden in a txt file in the background. At the moment, it appears to be PuTTy, and without additional instruction it does not do anything, but it is clearly a preparation for malicious actions.

Abuse categories

obfuscation

Code uses obfuscation techniques to hide its true purpose.

typosquatting

The package name is an typosquatting variant of a popular package.

Packages in the campaign

campaign:2025-06-hashidf