MAL-2026-11503
Dashboard / Malicious Package / MAL-2026-11503
MAL-2026-11503
Summary: Malicious code in instalogin1234 (PyPI)
Details: Source: amazon-inspector (4c7d01985e4b5c4afe1e4aafc0eb9a3d97feb1eacae68ef70adf962846392460) The package presents itself as a 'Modern Instagram CLI' but its `login` command displays a fake Instagram login prompt that reads a username and password via input() and POSTs the concatenated credentials to a hardcoded Discord channel (channel id 1246456414843437101) using a hardcoded Discord bot authorization token embedded in shell.py. After exfiltration it opens https://instagram.com/ in the user's browser as cover so the interaction appears to succeed. The advertised purpose is a cover story for credential harvesting; the Discord channel and bot token are attacker-controlled. Source: kam193 (f6ed64b38b3e872668e1d36a02c53136da1ab70ec9dacd2ac3b7d38c31794ebe) The package promises to be an Instagram CLI and offers "login". Entered credentials are sent to a Discord channel, and the user is presented with the Instagram website just opened in the browser. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-instalogin1234 Reasons (based on the campaign): - exfiltration-credentials
References: https://bad-packages.kam193.eu/pypi/package/instalogin1234, https://pypi.org/project/instalogin1234/0.0.1/
Affected packages
Package
Name: instalogin1234
Purl: pkg:pypi/instalogin1234
Affected ranges
Type: N/A
Events:
