{"id":"MAL-2026-1049","summary":"Malicious code in flycord (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (b2071af47a4b327550f5614253b291b893e0741e6f2ebe3b4378a4794696d211)\nWhen the user uses the provided library, this package silently reports basic information and the result of the user's action to a hardcoded, obfuscated URL. Given the lack of an opt-out possibility, collection of usernames, obfuscated target and not disclosing it anywhere, it cannot be classified as telemetry.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-02-flycord\n\n\nReasons (based on the campaign):\n\n\n - obfuscation\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - action-hidden-in-lib-usage\n","modified":"2026-02-26T16:02:47.712925Z","published":"2026-02-26T15:38:34Z","database_specific":{"malicious-packages-origins":[{"id":"pypi/2026-02-flycord/flycord","import_time":"2026-02-26T15:49:50.613017646Z","modified_time":"2026-02-26T15:38:34.49123Z","sha256":"b2071af47a4b327550f5614253b291b893e0741e6f2ebe3b4378a4794696d211","source":"kam193","versions":["1.2.4"]}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/flycord"}],"affected":[{"package":{"name":"flycord","ecosystem":"PyPI","purl":"pkg:pypi/flycord"},"versions":["1.2.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/flycord/MAL-2026-1049.json"}}],"schema_version":"1.7.3","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}