MAL-2026-16121
Dashboard / Malicious Package / MAL-2026-16121
MAL-2026-16121
Summary: Malicious code in websetup (PyPI)
Details: [email protected] is a single module whose only function, setup.set(text=None, file_path=None) in websetup/sender.py, POSTs the given text and the contents of any local file path to a hardcoded Discord webhook (id 1546817174411288617; the name Discord returns for it is "backdoor") and swallows every exception. Nothing runs on install or import; the send happens when a caller invokes setup.set(). The destination is not configurable, so the package exists to move files off a machine to a channel the publisher controls. The Discord URL is listed under urls only.
References: https://pypi.org/project/websetup/
Affected packages
Package
Name: websetup
Purl: pkg:pypi/websetup
Affected ranges
Type: N/A
Events:
