Skip to content

MALICIOUS (1) campaign cataloged at 2026-01-30(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-01-fastpi

Malicious copy of the legitimate FastAPI. The modification loads code encrypted in one of the attached files. The final, highly obfuscated code is most likely similar to the code from 2026-01-pypi-package-explore, with the exact behavior unknown.

Abuse categories

clones_real_package

The package is a clone of a legitimate package or library, but with malicious code added.

obfuscation

Code uses obfuscation techniques to hide its true purpose.

typosquatting

The package name is an typosquatting variant of a popular package.

Packages in the campaign

campaign:2026-01-fastpi