calc-x-x
discovered 2026-07-14NuGet DotnetTool downloader ("Calculator (GTA5RP calc)") published under operator pepegit666. Assembly calculator.dll, release tag "calculator". Ships gtaobus.pyc as DIRECT bytecode (Python 3.13) and adds an aiogram Telegram remote-control surface (screenshot/OCR, 36 unauthenticated handlers). On run it masquerades with a colored Russian console, sets AWS-style env vars, DoH-resolves GitHub hosts, and fetches the shared second-stage pepesoft.exe (Hugging Face -> GitHub Releases -> dormant BitTorrent). The payload writes host telemetry/inventory to Google Sheets and enforces an HWID/UUID ban-list kill switch. Only downloader WITHOUT the w32tm clock-resync UAC step and WITHOUT CleanupMeiFolders. Only the [email protected] version was explicitly disclosed; other package versions were not enumerated in the source.
Threat types
Malicious versions
- unspecified