MALICIOUS (1) campaign cataloged at 2026-07-22(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-07-make-helper¶
The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files.
Abuse categories¶
files_exfiltration
Campaign uses files_exfiltration.
obfuscation
Code uses obfuscation techniques to hide its true purpose.
uses-telegram-bot
Telegram Bot is used for malicious purposes
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
-
hxxps://key-2qfm.vercel.app/api/key -
key-2qfm.vercel.app