-= Per source details. Do not edit below this line.=-
The package reimagined-broccoli ships a benign-looking stub at reimagined_broccoli/main.py that only prints a success message. The tarball also ships redis.zip (declared in MANIFEST.in), which contains a second main.py, an opaque native ELF redis.so, and a .env. The package exposes a single console-script reimagined-broccoli whose entry point runs start.sh, which executes unzip -o "$SCRIPT_DIR/redis.zip" — overwriting the shipped stub — and then python3 "$SCRIPT_DIR/main.py", invoking the extracted payload alongside redis.so. There is no hash or signature verification of the archive contents. The package metadata is placeholder (Your Name, an auto-generated repository slug) and the file name redis.so does not correspond to the Redis project. The visible Python source is a decoy; the code actually executed on CLI invocation is the opaque bundled binary/script pair inside the archive. This is the extract-overwrite-execute dropper shape carrying an unverifiable native payload from a placeholder-author publisher.
In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-kimichat
Reasons (based on the campaign):
0.1.0Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H