Malicious code in turbod (PyPI)
-= Per source details. Do not edit below this line.=-
Starting version 1.0.7, the package contains obfuscated code and embedded binary that is executed during the import, sharing many similarities with package oxntime. The embedded seems to act as a guard for further execution, with some sandbox evasion techniques and time-based actions.
Prior to 1.0.7, the package offered obfuscation techniques.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-oxntime
Reasons (based on the campaign):
obfuscation
The package contains code to detect if it is running in a sandbox environment.
target:android
covering-tracks
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(PoC 존재) | ×1.20 |
| VPI | 66.00 |
VPI 공식 vpi-v1 기준