MALICIOUS (1) campaign cataloged at 2026-08-09(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-08-kotanku¶
During import, the package exfiltrates cryptocurrency wallet files.
Abuse categories¶
exfiltration_crypto
The package attempts to steal sensitive cryptocurrency-related data, like wallet keys.
uses-telegram-bot
Telegram Bot is used for malicious purposes