{"id":"MAL-2026-10702","summary":"Malicious code in discordia-telemetria (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d7b7d95c58f4a5203f542a11bc6e8ea0ff4d55bf22b2db938b563f169a732265)\nsetup.py contains a base64-encoded shell command that decodes to a curl fetch of an opaque binary from https://gaming-telemetry.com/v1/download, chmods it executable, and runs it. The payload invocation _run_payload(\"module\") is called at top-level module scope and is additionally wired into CustomInstall, CustomBuildPy, and CustomDevelop cmdclasses so it fires on any pip install, build, or develop path. The fetch destination is not a publisher-owned domain, the fetched bytes are not pinned or hash-verified, and the shell command is deliberately hidden behind base64 encoding. Installing this package hands remote code execution on the installer's machine to whoever controls gaming-telemetry.com.\n\n## Source: kam193 (ab73f38fc09955a1adcf493615ca1b8d6f3dedb2ae53d232c4c52b9aee9d26ee)\nDuring installation, the package downloads and executes a remote executable. Before 0.1.5, the code contained local-only tests of malicious behaviour.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-discord-telemetry\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - Downloads and executes a remote executable.\n\n\n - malware\n","modified":"2026-07-28T14:37:29.192465834Z","published":"2026-07-16T16:25:06Z","database_specific":{"malicious-packages-origins":[{"source":"kam193","sha256":"ab73f38fc09955a1adcf493615ca1b8d6f3dedb2ae53d232c4c52b9aee9d26ee","import_time":"2026-07-16T17:32:38.467456057Z","id":"pypi/2026-07-discord-telemetry/discordia-telemetria","modified_time":"2026-07-16T16:25:06.946232Z","versions":["0.1.1","0.1.2"]},{"id":"IN-MAL-2026-010938","modified_time":"2026-07-28T13:39:08Z","versions":["0.1.1"],"source":"amazon-inspector","sha256":"d7b7d95c58f4a5203f542a11bc6e8ea0ff4d55bf22b2db938b563f169a732265","import_time":"2026-07-28T14:20:00.103123613Z"}],"iocs":{"domains":["gaming-telemetry.com"],"urls":["https://gaming-telemetry.com/v1/beaconafter","https://gaming-telemetry.com/v1/download"]}},"references":[{"type":"WEB","url":"https://www.virustotal.com/gui/file-analysis/ZWM2MzcwMWE4NzM5ZjY2MGYzZjBiYTY4NjA0Y2E4YmE6MTc4NDIxMDQzMA=="},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/discordia-telemetria"},{"type":"PACKAGE","url":"https://pypi.org/project/discordia_telemetria/0.1.1/"}],"affected":[{"package":{"name":"discordia-telemetria","ecosystem":"PyPI","purl":"pkg:pypi/discordia-telemetria"},"versions":["0.1.1","0.1.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"68eca2263970b775c24801ac5c2f6e3f35bbe84a795e40bd50588e809fdd515d","tlsh":"f4117d25c13720784ac50ab045d78ea1ceb37f177e40abd939fe26544f5b031d419097","path":"setup.py"}],"package_integrity":[{"hashes":{"sha256":"0b77c1367cfe86b8ccaeadb4ec5aab49e2efca06d54e99c89117e520b2434fbd","blake2b_256":"b93b1f80f37f4d25136b21b0b04974a31bea3649f9612d4013adce0a658855e1","md5":"d474e956129013107aed897113665d6a"},"filename":"discordia_telemetria-0.1.1.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discordia-telemetria/MAL-2026-10702.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}