Skip to content

MALICIOUS (1) package from Python Package Index.

  1. The campaign has clearly malicious intent, like infostealers.

updateuuid4

  1. May not be available. See more in pypi-json-data repository.
  2. Version numbers are currently not tracked. Assume all versions are affected.

Campaign data

Campaign information may not always be 100% accurate for every related package.

Campaign description

The package, with an innocent looking name, has as the only functionality reporting to a Telegram channel given username and password. The functionality is in the "HeadersUpdate" class, that also looks like attempting to look innocent. The code does nothing more than reporting given credentials through a bot using the name "hitlercute_bot".

See more details on the campaign page.

infostealer

Campaign targets infostealer.