{"id":"MAL-2026-10701","summary":"Malicious code in discord-telemetry (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (225e2e6a53c221447d09b6259d38d079c519056851186eb72405cb2904072c0b)\nNo a static rule matches or traced code paths indicate exfiltration, install-time code execution, credential theft, silent-relay, backdoor, or self-propagation behavior in this package version. The package name references 'discord' and 'telemetry', but a name alone is not a supply-chain threat and this version's contents do not exhibit any of the fingerprints (browser credential-store enumeration, Discord leveldb session theft, hardcoded C2 endpoint, install-time fetch-and-execute) that would justify escalation.\n\n## Source: kam193 (b8a926675ed9f43b0067def4bd625208d08a08c8750fd3c2f9f7bfd6138e3d4d)\nDuring installation, the package downloads and executes a remote executable. Before 0.1.5, the code contained local-only tests of malicious behaviour.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-discord-telemetry\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - Downloads and executes a remote executable.\n\n\n - malware\n","modified":"2026-08-05T07:21:40.905995304Z","published":"2026-07-16T14:12:05Z","database_specific":{"iocs":{"urls":["https://gaming-telemetry.com/v1/beaconafter","https://gaming-telemetry.com/v1/download"],"domains":["gaming-telemetry.com"]},"malicious-packages-origins":[{"source":"kam193","versions":["0.1.0","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5"],"id":"pypi/2026-07-discord-telemetry/discord-telemetry","import_time":"2026-07-16T14:43:45.227465231Z","modified_time":"2026-07-16T14:12:05.940988Z","sha256":"b8a926675ed9f43b0067def4bd625208d08a08c8750fd3c2f9f7bfd6138e3d4d"},{"id":"IN-MAL-2026-013311","import_time":"2026-08-05T07:06:40.788672012Z","modified_time":"2026-08-05T06:05:01Z","sha256":"1bc82ff7d282075bebc715bfa3671b1b1501752fd1d9acc8227f0a7ac45b1aac","source":"amazon-inspector","versions":["0.1.3"]},{"versions":["0.1.0"],"id":"IN-MAL-2026-013314","import_time":"2026-08-05T07:06:40.950072357Z","modified_time":"2026-08-05T06:05:27Z","sha256":"225e2e6a53c221447d09b6259d38d079c519056851186eb72405cb2904072c0b","source":"amazon-inspector"},{"import_time":"2026-08-05T07:06:40.743713703Z","modified_time":"2026-08-05T06:04:55Z","sha256":"3841906767dc86fa36819ed8d5b85af1f831ea0284f5a51da6ca25f8069be30e","source":"amazon-inspector","versions":["0.1.2"],"id":"IN-MAL-2026-013310"},{"source":"amazon-inspector","versions":["0.1.1"],"id":"IN-MAL-2026-013313","import_time":"2026-08-05T07:06:40.894856935Z","modified_time":"2026-08-05T06:05:17Z","sha256":"b6e8738505f6ba76bfb0d93b9f9f5eb2ea95fdf5fd8cfe4e4cbe6a6b1e4fc023"},{"sha256":"f97417f974a7b0ca7ee05e859354c3aca4d26c656773cc494e09be027b1e8449","source":"amazon-inspector","versions":["0.1.4"],"id":"IN-MAL-2026-013312","import_time":"2026-08-05T07:06:40.835615734Z","modified_time":"2026-08-05T06:05:08Z"}]},"references":[{"type":"WEB","url":"https://www.virustotal.com/gui/file-analysis/ZWM2MzcwMWE4NzM5ZjY2MGYzZjBiYTY4NjA0Y2E4YmE6MTc4NDIxMDQzMA=="},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/discord-telemetry"},{"type":"PACKAGE","url":"https://pypi.org/project/discord-telemetry/0.1.3/"},{"type":"PACKAGE","url":"https://pypi.org/project/discord-telemetry/0.1.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/discord-telemetry/0.1.2/"},{"type":"PACKAGE","url":"https://pypi.org/project/discord-telemetry/0.1.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/discord-telemetry/0.1.4/"}],"affected":[{"package":{"name":"discord-telemetry","ecosystem":"PyPI","purl":"pkg:pypi/discord-telemetry"},"versions":["0.1.0","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discord-telemetry/MAL-2026-10701.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"md5":"c96680627128317fe27b42657736a0ad","sha256":"98d2b5e629641a5c55c9d5879ebae87254da063a6d712a575a6420925b6f8fd8","blake2b_256":"0aa49c33ad2f8e2f984eb48ad4d78b1dc4e558555c24205cb3ee974d995d3797"},"filename":"discord_telemetry-0.1.3.tar.gz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}