MAL-2026-253
Dashboard / Malicious Package / MAL-2026-253
MAL-2026-253
Published: 14 Jan 2026Last Modified: 14 Jan 2026
Summary: Malicious code in clipcord (PyPI)
Details: Source: kam193 (fca6ce37489de021bfea975a55751ad244552b7868a4e534f955d30a0efb1770) Package collects and exfiltrates Discord credentials from multiple sources Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-06-soupclaw Reasons (based on the campaign): - exfiltration-generic - exfiltration-env-variables - exfiltration-browser-data - exfiltration-credentials
Affected packages
Package
Name: clipcord
Purl: pkg:pypi/clipcord
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.7.0
1.7.1
1.7.2
