MAL-2026-10701
Dashboard / Malicious Package / MAL-2026-10701
MAL-2026-10701
Summary: Malicious code in discord-telemetry (PyPI)
Details: Source: amazon-inspector (225e2e6a53c221447d09b6259d38d079c519056851186eb72405cb2904072c0b) No a static rule matches or traced code paths indicate exfiltration, install-time code execution, credential theft, silent-relay, backdoor, or self-propagation behavior in this package version. The package name references 'discord' and 'telemetry', but a name alone is not a supply-chain threat and this version's contents do not exhibit any of the fingerprints (browser credential-store enumeration, Discord leveldb session theft, hardcoded C2 endpoint, install-time fetch-and-execute) that would justify escalation. Source: kam193 (b8a926675ed9f43b0067def4bd625208d08a08c8750fd3c2f9f7bfd6138e3d4d) During installation, the package downloads and executes a remote executable. Before 0.1.5, the code contained local-only tests of malicious behaviour. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-discord-telemetry Reasons (based on the campaign): - The package overrides the install command in setup.py to execute malicious code during installation. - Downloads and executes a remote executable. - malware
References: https://www.virustotal.com/gui/file-analysis/ZWM2MzcwMWE4NzM5ZjY2MGYzZjBiYTY4NjA0Y2E4YmE6MTc4NDIxMDQzMA==, https://bad-packages.kam193.eu/pypi/package/discord-telemetry, https://pypi.org/project/discord-telemetry/0.1.3/, https://pypi.org/project/discord-telemetry/0.1.0/, https://pypi.org/project/discord-telemetry/0.1.2/, https://pypi.org/project/discord-telemetry/0.1.1/, https://pypi.org/project/discord-telemetry/0.1.4/
Affected packages
Package
Name: discord-telemetry
Purl: pkg:pypi/discord-telemetry
Affected ranges
Type: N/A
Events:
