Skip to content

MALICIOUS (1) campaign cataloged at 2025-06-22(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2025-06-hashidf

If ran as a module, the package silently starts a binary hidden in a txt file in the background. At the moment, it appears to be PuTTy, and without additional instruction it does not do anything, but it is clearly a preparation for malicious actions.

Abuse categories

obfuscation

Campaign uses obfuscation.

typosquatting

Campaign uses typosquatting.

Packages in the campaign

campaign:2025-06-hashidf