Skip to content

MALICIOUS (1) campaign cataloged at 2026-09-17(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-09-pyjstat-smooth

The package hides code to exfiltrate specific files from the user's machine. The used file paths suggest it was intended to be used in a CTF-like environment.

Abuse categories

clones_real_package

The package is a clone of a legitimate package or library, but with malicious code added.

files_exfiltration

Campaign uses files_exfiltration.

obfuscation

Code uses obfuscation techniques to hide its true purpose.

targetted-attack

Campaign uses targetted-attack.

References

Referenced resources may include blog posts about the campaign, malware analysis, sandbox reports, or other relevant information.

Packages in the campaign

campaign:2026-09-pyjstat-smooth