Objectives
hostile severity, 98% confident.
command-and-control/dropper
Complete dropper lifecycle (Fetch + Write + Execute)
hostile severity, 95% confident.
evasion/process/injection
Node-API addon with shellcode injection capability
hostile severity, 95% confident.
exfiltration
Sensitive file read and exfiltration (JS)
hostile severity, 98% confident.
supply-chain/hidden-payload
PyPI package fetches writes executes payload
suspicious severity, 100% confident.
anti-analysis/geofencing
CIS region timezone offset checks
suspicious severity, 90% confident.
anti-static/obfuscation
Instantiating an object via 'this' with bracket
suspicious severity, 100% confident.
anti-static/obfuscation/eval
Generic Function constructor usage
suspicious severity, 90% confident.
anti-static/obfuscation/string
Massive string concatenation operations
suspicious severity, 92% confident.
anti-static/pack
Node imports payload decoder
suspicious severity, 90% confident.
command-and-control/backdoor/tasking
Node C2 command response dispatch
suspicious severity, 90% confident.
command-and-control/remote-command
WebSocket sends host environment context
suspicious severity, 90% confident.
credential-access/env/secrets
process.env secret-name filter regex
suspicious severity, 94% confident.
evasion/quarantine-removal
Rust xattr quarantine delete
suspicious severity, 92% confident.
evasion/security-bypass
checkServerIdentity returns undefined/null
suspicious severity, 90% confident.
execution/interpreter/eval
Global object assignment (root/self/global)
suspicious severity, 93% confident.
exfiltration/http
Python raw socket stream
suspicious severity, 93% confident.
exfiltration/stealer/host-profile
TS host profile fields
suspicious severity, 90% confident.
supply-chain/impersonation
Suspicious npm package clone detected
suspicious severity, 96% confident.
supply-chain/recon-exfil/oast
Node encodes host profile JSON as base64
Micro-behaviors
suspicious severity, 92% confident.
process/create/shell
WScript Run hides launched process
20 of 191 traits shown
Identity
| SHA-256 | 3cf5b4b45eca69e643cfd90bc9590952d18677b0fdf2a65829135f072c51c7fe |
|---|---|
| Canonical SHA-256 | 000877d1b0f3d96fa96340eacd5e83109ed2166e0698a934c1ed2bd2a5d78e51 |
| Filename | qairt_visualizer-0.11.0-py3-none-macosx_11_0_arm64.whl |
| Package | qairt-visualizer |
| Version | 0.11.0-py3-none-macosx_11_0_arm64 |
Origin
| Source | harvest |
|---|---|
| Feed | pypi.org |
| Ecosystem | python |
| Domain | pythonhosted.org |
Timeline
| First seen | 14 Jun 2026 16:43 UTC |
|---|---|
| First analyzed | 14 Jun 2026 17:02 UTC |
| Last analyzed | 14 Jun 2026 17:02 UTC |
| Last updated | 14 Jun 2026 17:02 UTC |
Labeling
| Label | unknown |
|---|---|
| Label source | harvest |
| Traits version | 061e3 |
Not seeing what you expected? Let us know