Skip to content

MALICIOUS (1) campaign cataloged at 2026-08-06(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-08-alphalend-layouts

During import, the package exfiltrates sensitive files with SUI private keys to a private GitHub repository. This action is also triggered on every Python startup due to leveraging PTH files.

Abuse categories

abuses-pth

The package uses .pth files, sitecustomize or usercustomize modules to execute malicious code during Python startup, even without importing the package code manually.

crypto-related

Malicious activity is related to cryptocurrencies or blockchain, e.g. stealing crypto wallets.

exfiltration_crypto

The package attempts to steal sensitive cryptocurrency-related data, like wallet keys.

files_exfiltration

Campaign uses files_exfiltration.

obfuscation

Code uses obfuscation techniques to hide its true purpose.

URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.

  • hxxps://github.com/futongwan/alphalend-layouts

Packages in the campaign

campaign:2026-08-alphalend-layouts