HIGHLY_SUSPICIOUS (1) campaign cataloged at 2026-01-20(2).
- Packages that are likely malicious, but due to the obfuscation level, lack of time or clear indicators it's hard to say what exactly they do; the highest risk of false positives.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-01-old-web3http¶
Package is a clone of legitimate httpx package. The only difference is that the clone contains an encrypted ZIP archive. The content of the archive is related to cryptocurrencies, but seems not to have any active malicious content.
Abuse categories¶
clones_real_package
The package is a clone of a legitimate package or library, but with malicious code added.
crypto-related
Malicious activity is related to cryptocurrencies or blockchain, e.g. stealing crypto wallets.
obfuscation
Code uses obfuscation techniques to hide its true purpose.
other
Campaign uses other.