MAL-2026-16121

    Dashboard / Malicious Package / MAL-2026-16121

    MAL-2026-16121

    Published: 9 Sept 2026Last Modified: 10 Sept 2026

    Summary: Malicious code in websetup (PyPI)

    Details: [email protected] is a single module whose only function, setup.set(text=None, file_path=None) in websetup/sender.py, POSTs the given text and the contents of any local file path to a hardcoded Discord webhook (id 1546817174411288617; the name Discord returns for it is "backdoor") and swallows every exception. Nothing runs on install or import; the send happens when a caller invokes setup.set(). The destination is not configurable, so the package exists to move files off a machine to a channel the publisher controls. The Discord URL is listed under urls only.

    Affected packages

    Package

    Name: websetup

    Purl: pkg:pypi/websetup

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0