MALICIOUS (1) campaign cataloged at 2026-05-03(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-05-gauth-client¶
Package impersonates Google and attempts to exfiltrate various credential files. It also setups PTH file for automated start during Python initialization. In the analyzed version, the exfiltration target was set as localhost suggesting it's not the final code.
Abuse categories¶
exfiltration_credentials
The package attempts to steal credentials, like passwords or API keys.
files_exfiltration
Campaign uses files_exfiltration.
impersonation
Campaign uses impersonation.