{"id":"MAL-2026-11503","summary":"Malicious code in instalogin1234 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4c7d01985e4b5c4afe1e4aafc0eb9a3d97feb1eacae68ef70adf962846392460)\nThe package presents itself as a 'Modern Instagram CLI' but its `login` command displays a fake Instagram login prompt that reads a username and password via input() and POSTs the concatenated credentials to a hardcoded Discord channel (channel id 1246456414843437101) using a hardcoded Discord bot authorization token embedded in shell.py. After exfiltration it opens https://instagram.com/ in the user's browser as cover so the interaction appears to succeed. The advertised purpose is a cover story for credential harvesting; the Discord channel and bot token are attacker-controlled.\n\n## Source: kam193 (f6ed64b38b3e872668e1d36a02c53136da1ab70ec9dacd2ac3b7d38c31794ebe)\nThe package promises to be an Instagram CLI and offers \"login\". Entered credentials are sent to a Discord channel, and the user is presented with the Instagram website just opened in the browser.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-instalogin1234\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-credentials\n","modified":"2026-08-04T22:05:26.021875566Z","published":"2026-08-03T20:34:47Z","database_specific":{"malicious-packages-origins":[{"sha256":"f6ed64b38b3e872668e1d36a02c53136da1ab70ec9dacd2ac3b7d38c31794ebe","source":"kam193","versions":["0.0.1"],"id":"pypi/2026-08-instalogin1234/instalogin1234","import_time":"2026-08-03T20:52:49.256603933Z","modified_time":"2026-08-03T20:34:47.160662Z"},{"id":"IN-MAL-2026-011002","import_time":"2026-08-04T21:33:13.0913301Z","modified_time":"2026-08-04T21:18:04Z","sha256":"4c7d01985e4b5c4afe1e4aafc0eb9a3d97feb1eacae68ef70adf962846392460","source":"amazon-inspector","versions":["0.0.1"]}],"iocs":{"urls":["https://discord.com/api/v9/channels/1246456414843437101/messages"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/instalogin1234"},{"type":"PACKAGE","url":"https://pypi.org/project/instalogin1234/0.0.1/"}],"affected":[{"package":{"name":"instalogin1234","ecosystem":"PyPI","purl":"pkg:pypi/instalogin1234"},"versions":["0.0.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"instalogin/shell.py","sha256":"8f51f1e171a54506697273ee24209e60720f4a9e0b9eae3c75731854f9ec87ff","tlsh":"735134229db65472227aca1ce8178021fa4637173ab8b52f7a2ca63c4ff885491524fd"}],"package_integrity":[{"hashes":{"md5":"deac6bd35f16246fcf4e138c4ae0ed26","sha256":"21431541485d6efd5f012502856311aa3a08fa10294a0ba1326b4a86299ce177","blake2b_256":"1ffbb59b80fa91689d01dc0dea6d5960ea2566ff89cb7c29ace94fe7da03041d"},"filename":"instalogin1234-0.0.1-py3-none-any.whl"},{"filename":"instalogin1234-0.0.1.tar.gz","hashes":{"md5":"0ac3eb7cbdc5b53850ed1e9c7082c22b","sha256":"fdd4bbaccd1004f29e1822fb5cdc05b5f07541b641a62babadee31d89d6925c0","blake2b_256":"3113326a0cf977ca33b69c7393f4732402b6da7e8fa82697aa5cf295d5fbbc90"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/instalogin1234/MAL-2026-11503.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}