Supply-chain threat intelligence
Risk score
92
Indexed incident for yuzo (pypi).
Package contains an infostealer and is clearly prepared for using it. Different versions present different variations, newer are based on CStealer. The exfiltration target is a hardcoded discord webhook
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-09-suyo
Reasons (based on the campaign):
infostealer
infostealer:cstealer
exfiltration-browser-data
Indicators
Timeline