MAL-2026-11050
Dashboard / Malicious Package / MAL-2026-11050
MAL-2026-11050
Summary: Malicious code in discordnv (PyPI)
Details: Source: amazon-inspector (2f79139609558d677545faa7d5f1d30ec31a54abe9fba990117ec0d27ea3ba48) On `import discordnv`, __init__.py invokes main_entry() which hides the console window, walks Discord/Chrome/Edge/Brave/Opera/Yandex/Firefox LevelDB/SQLite stores to extract Discord authentication tokens, reads and DPAPI-decrypts Roblox `robloxcookies.dat`, and POSTs the harvested credentials to a hardcoded Discord webhook at discord.com/api/webhooks/1528403989983662194/... and a Google Apps Script endpoint at script.google.com/macros/s/AKfycbwa.../exec. add_to_startup() writes an HKCU\Software\Microsoft\Windows\CurrentVersion\Run entry named `discordnv` pointing at the invoking Python/exe so the stealer re-runs on every user logon. All operations are wrapped in bare try/except to swallow errors and avoid alerting the user. The package's advertised purpose (a Roblox DataStore helper) is unrelated to the observed behavior. Source: kam193 (d28ded2ca28c0182385e9dccf5939e883fd5f18dfa702ca912429270a92f3646) The package exfiltrates Roblox cookies and Discord tokens from the victim machine. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-spaysrbdata Reasons (based on the campaign): - infostealer
References: https://bad-packages.kam193.eu/pypi/package/discordnv, https://pypi.org/project/discordnv/0.8.0/
Affected packages
Package
Name: discordnv
Purl: pkg:pypi/discordnv
Affected ranges
Type: N/A
Events:
