Note: This report is updated by a verification record
Multiple low confidence YARA matches, but no strong evidence to classify as malware.
The package contains a malicious .pth file (litellm_init.pth, 34,628 bytes) that automatically executes a credential-stealing script every time the Python interpreter starts.
Note: This report is updated by a verification record
The package is not a malware. Multiple YARA rules have matched, but they are all low confidence. The YARA rules exotic_tld and post_exotic_tld matched because the package interacts with api.together.xyz. The discord_bot rule matched because the package has some files related to Discord interactions. The rule hidden_short_path_temp matched because the package uses /tmp/.npm_mcp_cache as a cache directory. The rules base64_commands, suspected_data_stealer, hardcoded_host_port_over_10k, xor_terms, http_hardcoded_ip and hardcoded_ip_port have also matched, but these are not strong indicators of malware on their own.