MALICIOUS (1) campaign cataloged at 2026-06-08(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-06-spl-token-py¶
During import, the package exfiltrates sensitive data (credentials, SSH keys, cryptowallet's data). It also establishes persistence via a cronjob.
Abuse categories¶
crypto-related
Malicious activity is related to cryptocurrencies or blockchain, e.g. stealing crypto wallets.
exfiltration_credentials
The package attempts to steal credentials, like passwords or API keys.
exfiltration_crypto
The package attempts to steal sensitive cryptocurrency-related data, like wallet keys.
exfiltration_env_variables
Campaign uses exfiltration_env_variables.
exfiltration_ssh_keys
Campaign uses exfiltration_ssh_keys.
persistence
Campaign uses persistence.
sandbox-detection
The package contains code to detect if it is running in a sandbox environment.
typosquatting
The package name is an typosquatting variant of a popular package.
uses-telegram-bot
Campaign uses uses-telegram-bot.