{"id":"MAL-2026-6549","summary":"Malicious code in discord-token-generator (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (93b4fe1006dee186a1cbe4513b0f0c127912724aed5b3caf6bca4b0f27294b99)\nDuring import, package executes the embedded executable. It is an infostealer named internally as \"NBSteal\", focused on exfiltrating data from browsers, Telegram, Discord, Roblox and other gaming platforms, and other credentials.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-discord-token-generator\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n - files-exfiltration\n\n\n - obfuscation\n\n\n - exfiltration-browser-data\n\n\n - malware\n\n\n - target:telegram\n\n\n - exfiltration-credentials\n","modified":"2026-06-27T21:46:00.389782022Z","published":"2026-06-27T20:52:32Z","database_specific":{"malicious-packages-origins":[{"source":"kam193","sha256":"93b4fe1006dee186a1cbe4513b0f0c127912724aed5b3caf6bca4b0f27294b99","import_time":"2026-06-27T21:27:44.805103099Z","modified_time":"2026-06-27T20:52:32.20789Z","versions":["1.0.0","1.0.1","1.0.2","1.0.3"],"id":"pypi/2026-06-discord-token-generator/discord-token-generator"}],"iocs":{"urls":["https://nbbtest.bnfdkfq156.workers.dev/"],"domains":["nbbtest.bnfdkfq156.workers.dev"]}},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/c31597963a8e83fc068a70a6187abc4d8fb1a67b318fc20aebb298ad97377783/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/discord-token-generator"}],"affected":[{"package":{"name":"discord-token-generator","ecosystem":"PyPI","purl":"pkg:pypi/discord-token-generator"},"versions":["1.0.0","1.0.1","1.0.2","1.0.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discord-token-generator/MAL-2026-6549.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}