Open-source atomic malware analysis

Analyze another

lfx-1.11.0.dev9-py3-none-any.whl

WHL
Verdict: BENIGN
AI Legitimate Langflow package with standard components
Python stealer context with dropper: lfx-1.11.0.dev9-py3-none-any.whl:0x56e
Dynamic module import followed by
Python raw socket stream
lfx-1.11.0.dev9-py3-none-any.whl whl
0 PK������BP��������������lfx/__init__.py�PK������BPt��Regex for database secrets

Well-known

notable severity, 100% confident.
lib Contains the string "urllib3"

Objectives

suspicious severity, 95% confident.
anti-static/obfuscation/reflection Dynamic module import followed by
suspicious severity, 92% confident.
command-and-control/backdoor/rat Python C2 upload endpoint
suspicious severity, 75% confident.
credential-access/cloud/token AWS credential directory reference
suspicious severity, 92% confident.
execution/interpreter Python runtime compile call
suspicious severity, 93% confident.
exfiltration/http Python raw socket stream
suspicious severity, 90% confident.
supply-chain/credential-theft Composer auth.json reference
notable severity, 97% confident.
credential-access/cloud Python reads AWS shared credentials
notable severity, 95% confident.
execution/autoinstall pip install using sys.executable

Micro-behaviors

notable severity, 92% confident.
data/archive/extract Python ZIP archive extraction
notable severity, 95% confident.
fs/path/sensitive AWS config file path

Metadata

notable severity, 100% confident.
build site-packages directory reference

20 of 86 traits shown

Identity

SHA-256 267205206a290d0749680ced2b0ee8ec82505ee3cad84e580d9069dae816d721
Canonical SHA-256 0033538cc8d3825bdd0b7e181203185a2a69ceb5d6887de4bbfdd1bd141c3a5c
Filename lfx-1.11.0.dev9-py3-none-any.whl
Package lfx
Version 1.11.0.dev9

Timeline

First seen 15 Jun 2026 23:32 UTC
First analyzed 16 Jun 2026 23:31 UTC
Last analyzed 16 Jun 2026 23:31 UTC
Last updated 16 Jun 2026 23:31 UTC

Labeling

Label unknown
Label source forager
Traits version 27202