MALICIOUS (1) campaign cataloged at 2025-10-22(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2025-10-asynhttp¶
Packages silently decrypt content hidden in a dependency and load them as Python extension modules.
In the first wave, those are copies of legitimate aiohttp and aiohappyeyeballs packages. In the second wave, malicious packages created good-looking forks of legitimate rich and pigments packages.
Abuse categories¶
clons_real_package
The package is a clone of a real package, but with malicious code added.
exfiltration_generic
Campaign uses exfiltration_generic.
obfuscation
Campaign uses obfuscation.
typosquatting
Campaign uses typosquatting.
References¶
Referenced resources may include blog posts about the campaign, malware analysis, sandbox reports, or other relevant information.