MAL-2026-11050

    Dashboard / Malicious Package / MAL-2026-11050

    MAL-2026-11050

    Published: 24 Jul 2026Last Modified: 27 Aug 2026

    Summary: Malicious code in discordnv (PyPI)

    Details: Source: amazon-inspector (2f79139609558d677545faa7d5f1d30ec31a54abe9fba990117ec0d27ea3ba48) On `import discordnv`, __init__.py invokes main_entry() which hides the console window, walks Discord/Chrome/Edge/Brave/Opera/Yandex/Firefox LevelDB/SQLite stores to extract Discord authentication tokens, reads and DPAPI-decrypts Roblox `robloxcookies.dat`, and POSTs the harvested credentials to a hardcoded Discord webhook at discord.com/api/webhooks/1528403989983662194/... and a Google Apps Script endpoint at script.google.com/macros/s/AKfycbwa.../exec. add_to_startup() writes an HKCU\Software\Microsoft\Windows\CurrentVersion\Run entry named `discordnv` pointing at the invoking Python/exe so the stealer re-runs on every user logon. All operations are wrapped in bare try/except to swallow errors and avoid alerting the user. The package's advertised purpose (a Roblox DataStore helper) is unrelated to the observed behavior. Source: kam193 (d28ded2ca28c0182385e9dccf5939e883fd5f18dfa702ca912429270a92f3646) The package exfiltrates Roblox cookies and Discord tokens from the victim machine. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-spaysrbdata Reasons (based on the campaign): - infostealer

    Affected packages

    Package

    Name: discordnv

    Purl: pkg:pypi/discordnv

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.8.0
    MAL-2026-11050 | CVE-DB