AI
Legitimate llama.cpp source code distribution
Well-known
notable severity, 95% confident.
lib
nlohmann::json single-header source library
Objectives
suspicious severity, 95% confident.
anti-analysis/debugger-detect
Unix TracerPid debugger check
suspicious severity, 92% confident.
command-and-control/backdoor/tasking
Native exec read task tokens
suspicious severity, 92% confident.
exfiltration/stealer
Native environ harvest loop
suspicious severity, 85% confident.
supply-chain/metadata-anomaly
setup.py with abnormally high version number
notable severity, 90% confident.
evasion/file-hiding
Quoted hidden-dotfile path literal
notable severity, 100% confident.
evasion/kernel-hide/lkm
Derived ast condition
Micro-behaviors
notable severity, 90% confident.
communications/http/request
Performs HTTP request (urllib, requests, httpx)
notable severity, 100% confident.
communications/socket
Raw socket send call
notable severity, 90% confident.
data/compress
ZSTD_CCtx type
notable severity, 90% confident.
data/serialize
Python json.loads call
notable severity, 90% confident.
data/text/llm
LLM edit_file tool reference
notable severity, 95% confident.
dylib/load
LoadLibraryA call in source
notable severity, 92% confident.
os/msdos
DOS read file call
notable severity, 95% confident.
process/create
Create process (ANSI)
notable severity, 90% confident.
process/create/shell
system() function call
notable severity, 90% confident.
process/info
Get module handle
Metadata
notable severity, 92% confident.
build
actions/checkout workflow step
notable severity, 90% confident.
encoded-payload
Encoded payload detected: xor → base64
notable severity, 95% confident.
lang
Source imports subprocess module
20 of 52 traits shown
Identity
| SHA-256 | 2382c9aeba8782c5ed071ede52f48c089f67152c7461e3e0cd56cdc24ab77286 |
|---|---|
| Canonical SHA-256 | 0029616465e6d641c1e75a0e0e6e132f3ea6177593735d7f16c89e7edfbbe9a8 |
| Filename | llama_cpp_bin-9660.0.0.tar.gz |
| Package | llama-cpp-bin |
| Version | 9660.0.0 |
Origin
| Source | forager |
|---|---|
| Feed | pypi.org |
| Ecosystem | python |
| Domain | pythonhosted.org |
| URL | https://files.pythonhosted.org/packages/90/2d/08c021261d8c16c4bd0384e8448d5870cdafdda3f491dc1e927e67cc6ea7/llama_cpp_bin-9660.0.0.tar.gz |
Timeline
| First seen | 15 Jun 2026 23:31 UTC |
|---|---|
| First analyzed | 16 Jun 2026 16:12 UTC |
| Last analyzed | 16 Jun 2026 16:12 UTC |
| Last updated | 16 Jun 2026 16:12 UTC |
Labeling
| Label | unknown |
|---|---|
| Label source | forager |
| Traits version | 061e3 |
Not seeing what you expected? Let us know