Malicious code in quatres (PyPI)
-= Per source details. Do not edit below this line.=-
During import, the hidden code downloads and executes the second-stage code. After performing anti-analysis checks, it downloads a malicious executable and ensures its persistence.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-helu
Reasons (based on the campaign):
obfuscation
Downloads and executes a remote malicious script.
The package contains code to detect if it is running in a sandbox environment.
Downloads and executes a remote executable.
malware
persistence
covering-tracks
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(PoC 존재) | ×1.20 |
| VPI | 66.00 |
VPI 공식 vpi-v1 기준