-= Per source details. Do not edit below this line.=-
Importing the module, downloads and starts a malicious executable identified as infostealer.
Based on Telegram links, this is related to the 2025-12-synium campaign, but uses slightly different techniques.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-12-runtimeutils
Reasons (based on the campaign):
malware
Downloads and executes a remote executable.
infostealer
{
"iocs": {
"urls": [
"http://89.39.121.49:20578/Helper.exe"
],
"ips": [
"89.39.121.49"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2025-12-runtimeutils/runtimeutils",
"modified_time": "2025-12-21T14:03:30.5446Z",
"source": "kam193",
"sha256": "4d312906cc585fcd02b2ac0b52bb04a23b0294532e3625c7f5e27bf1e4b51e4a",
"versions": [
"1.0.2",
"1.0.1",
"1.0.0",
"1.0.2"
],
"import_time": "2025-12-21T14:37:49.461805313Z"
},
{
"id": "pypi/2025-12-runtimeutils/runtimeutils",
"modified_time": "2025-12-21T14:03:30.5446Z",
"source": "kam193",
"sha256": "a5da1962c4896546065e477eae3461c641d8cab05d4fdd375f7b26bef6d502fa",
"versions": [
"1.0.2",
"1.0.1",
"1.0.0",
"1.0.2"
],
"import_time": "2025-12-24T23:07:31.460845305Z"
}
]
}