Skip to content

HIGHLY_SUSPICIOUS (1) campaign cataloged at 2026-01-20(2).

  1. Packages that are likely malicious, but due to the obfuscation level, lack of time or clear indicators it's hard to say what exactly they do; the highest risk of false positives.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-01-old-web3http

Package is a clone of legitimate httpx package. The only difference is that the clone contains an encrypted ZIP archive. The content of the archive is related to cryptocurrencies, but seems not to have any active malicious content.

Abuse categories

clones_real_package

The package is a clone of a legitimate package or library, but with malicious code added.

crypto-related

Malicious activity is related to cryptocurrencies or blockchain, e.g. stealing crypto wallets.

obfuscation

Code uses obfuscation techniques to hide its true purpose.

other

Campaign uses other.

Packages in the campaign

campaign:2026-01-old-web3http