MAL-2026-251
Dashboard / Malicious Package / MAL-2026-251
MAL-2026-251
Published: 14 Jan 2026Last Modified: 14 Jan 2026
Summary: Malicious code in soupclaw (PyPI)
Details: Source: kam193 (d81f6899b3e1e16c0fd74656a7fb8cedfd711e9e68078d85ed95cdb10979e3d1) Package collects and exfiltrates Discord credentials from multiple sources Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-06-soupclaw Reasons (based on the campaign): - exfiltration-generic - exfiltration-env-variables - exfiltration-browser-data - exfiltration-credentials
Affected packages
Package
Name: soupclaw
Purl: pkg:pypi/soupclaw
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.7.1
1.7.2
1.7.3
