MAL-2026-11503

    Dashboard / Malicious Package / MAL-2026-11503

    MAL-2026-11503

    Published: 3 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in instalogin1234 (PyPI)

    Details: Source: amazon-inspector (4c7d01985e4b5c4afe1e4aafc0eb9a3d97feb1eacae68ef70adf962846392460) The package presents itself as a 'Modern Instagram CLI' but its `login` command displays a fake Instagram login prompt that reads a username and password via input() and POSTs the concatenated credentials to a hardcoded Discord channel (channel id 1246456414843437101) using a hardcoded Discord bot authorization token embedded in shell.py. After exfiltration it opens https://instagram.com/ in the user's browser as cover so the interaction appears to succeed. The advertised purpose is a cover story for credential harvesting; the Discord channel and bot token are attacker-controlled. Source: kam193 (f6ed64b38b3e872668e1d36a02c53136da1ab70ec9dacd2ac3b7d38c31794ebe) The package promises to be an Instagram CLI and offers "login". Entered credentials are sent to a Discord channel, and the user is presented with the Instagram website just opened in the browser. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-instalogin1234 Reasons (based on the campaign): - exfiltration-credentials

    Affected packages

    Package

    Name: instalogin1234

    Purl: pkg:pypi/instalogin1234

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.1
    MAL-2026-11503 | CVE-DB