MAL-2026-5329

    Dashboard / Malicious Package / MAL-2026-5329

    MAL-2026-5329

    Published: 8 Jun 2026Last Modified: 27 Aug 2026

    Summary: Malicious code in spaysdatarbx (PyPI)

    Details: Source: amazon-inspector (1bcaa4bf6f81efed82d35081ec059dfcd2f55e50b84f28d8b0ad4d8afe63089f) spaysdatarbx is a Windows infostealer disguised as a Roblox DataStore library. On `import spaysdata`, __init__.py invokes main_entry() (wrapped in try/except: pass to stay silent), which performs three malicious actions: (1) reads %USERPROFILE%/AppData/Local/Roblox/LocalStorage/robloxcookies.dat, DPAPI-decrypts it, and POSTs the plaintext Roblox session cookie to a hardcoded Discord webhook (https://discord.com/api/webhooks/1499336276762038292/...); (2) walks Discord, Chrome, Edge, Brave, Opera, Yandex, and Firefox profile directories, force-kills Discord with `taskkill /f /im Discord.exe` to release leveldb locks, AES-GCM-decrypts auth tokens with each browser's DPAPI master key, and POSTs every recovered token to the same webhook; (3) establishes persistence by copying itself to %APPDATA%\MySystemUtility\ and writing an HKCU\...\Run\MyPythonAutostartApp registry value that re-launches the stealer at every login, hiding the console window via ShowWindow(GetConsoleWindow(), 0). The package's advertised purpose ('Библиотека для работы с DataStore в Roblox') is a decoy — no DataStore functionality exists in main.py, only the stealer. Any developer who installs and imports this package has their Roblox session and all browser-stored Discord tokens sent to the attacker, plus a persistent autostart entry for ongoing theft. Source: kam193 (31b0b97326861aabb747f26e130a5dbda5ac78100fafbb3a3327b1981119e3a6) The package exfiltrates Roblox cookies from the victim machine. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-spaysrbdata Reasons (based on the campaign): - infostealer

    Affected packages

    Package

    Name: spaysdatarbx

    Purl: pkg:pypi/spaysdatarbx

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.3
    0.1.5
    MAL-2026-5329 | CVE-DB