Skip to content

MALICIOUS (1) campaign cataloged at 2026-05-09(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-05-ggfmttygl

Package is disguised as a utility, but in fact loads encrypted code as modules. However, loading it requires knowing the decryption key which is not included in the package.

Abuse categories

obfuscation

Code uses obfuscation techniques to hide its true purpose.

through_dependency

The malicious code is intentionally included in a dependency of the package

Packages in the campaign

campaign:2026-05-ggfmttygl