malware pypi
hermes-px
discovered 2026-04-06hermes-px is identified in the SafeDep analysis "Malicious hermes-px on PyPI Steals AI Conversations". >-
Threat types
credential_stealer data_exfiltration
Malicious versions
- 0.1.0
Campaigns
Indicators
- domain prod.universitecentrale.netcommunicates-with
- domain urlvoelpilswwxkiosey.supabase.cocommunicates-with
- domain chat.universitecentrale.netcommunicates-with
- ipv4 146.0.0.0communicates-with
- sha1 333e5b7c412736685b3c296a58663a7763744949indicates
- sha1 4c385d4376314b24793b6b4e3526783f72383667indicates
- sha1 2a6e3839766d215e40785f6b277dc2a34d4e2f71indicates
- sha1 442158353951337678587c236567276e767a3d39indicates
- sha1 3f3922326c646a2d2f78703073224a3e4a366761indicates
- sha1 3c335f732e6f5c3b48665745325c572b25724a60indicates
- sha1 2968623b3a4c275d544149674522663559617b74indicates
Techniques
- ttp T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Toolsuses
- ttp T1059.006 Command and Scripting Interpreter: Pythonuses
- ttp T1552.001 Unsecured Credentials: Credentials In Filesuses
- ttp T1041 Exfiltration Over C2 Channeluses
- ttp T1071.001 Application Layer Protocol: Web Protocolsuses
- ttp T1102 Web Serviceuses
