MALICIOUS (1) campaign cataloged at 2026-02-23(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-02-request-httpx-4¶
The package contains a Telegram bot running allowing for remote access. This functionality is disclosed in the readme, but the package name clearly indicates it's either a dependency confusion attempt or it's intended to be hidden from the user in the installed environment.
Abuse categories¶
dependency-confusion
An attempt to exploit dependency confusion
files_exfiltration
Campaign uses files_exfiltration.
remote_commands
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.