Skip to content

MALICIOUS (1) campaign cataloged at 2026-10-10(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-10-webreader

In this campaign, the main package (webreader) has an embeded pickle disguised as a config. A related dependency (pafer) contains code to load the pickle. During unpickling, malicious code embeded in the pickle file is automatically executed. It then establishes persistence via a PTH file and downloads the next stage payload. It finally acts like a RAT, allowing remote exfiltration and code execution.

Abuse categories

RAT

Malicious activity is typical for Remote Access Trojans (RATs).

abuses-pth

The package uses .pth files, sitecustomize or usercustomize modules to execute malicious code during Python startup, even without importing the package code manually.

files_exfiltration

Campaign uses files_exfiltration.

obfuscation

Code uses obfuscation techniques to hide its true purpose.

persistence

Campaign uses persistence.

remote_commands

The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

remote_script

Downloads and executes a remote malicious script.

through_dependency

The malicious code is intentionally included in a dependency of the package

URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.

  • hxxps://api.npoint.io/40e32d283a9d97e59252/a

  • frjmzbjbhwvtdnsuodmu.supabase.co

Packages in the campaign

campaign:2026-10-webreader