Skip to content

HIGH_RISK_HACKING_TOOLS (1) campaign cataloged at 2026-03-20(2).

  1. Packages that are very likely to be used to build or as part of a malware, in most cases. They are not malicious on their own, but are quite a good indicator of something suspicious
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-03-geekennedy

Packages in this campaign seem not to be malicious on their own but altogether create an exfiltration toolkit created by one user, e.g. collecting process data and potentially using DNS as C2. The malicious intention is, however, not confirmed at the moment.

Package nspack additionally notifies upon importing a domain known for malicious activity with the package and hostname.

Abuse categories

basic_exfiltration

The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.

  • 1r.vc

  • gcloudns.net

Packages in the campaign

campaign:2026-03-geekennedy