MAL-2024-11578

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discould/MAL-2024-11578.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-11578
Published
2024-09-04T21:25:32Z
Modified
2026-03-19T12:52:42Z
Summary
Malicious code in discould (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (bb38a630a1e0c6e81089ebb95d407d438c932c26527fde69e9c304305d267ca9)

Importing a module starts downloading and executing an infostealer, widely identified by AV/sandboxes.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-08-embeds-RealtekHDAudioManager

Reasons (based on the campaign):

  • infostealer

  • Downloads and executes a remote executable.

Database specific
{
    "iocs": {
        "urls": [
            "https://github.com/holdthatcode/host/raw/main/howl.exe",
            "https://github.com/holdthatcode/host/raw/main/menu.exe",
            "https://raw.githubusercontent.com/bloodstainedvvs/host/main/code.exe",
            "https://github.com/bloodstainedvvs/host/raw/main/zwerve.exe",
            "https://cdn.discordapp.com/attachments/1276975489780809812/1282787632082059359/zwerve.exe?ex=66e0a094&is=66df4f14&hm=f4604d9783911e770716516e30d4f665214449f46aa2c5a59afc4bda7042bfba&",
            "https://github.com/holdthatcode/e/raw/main/code.exe",
            "https://github.com/holdthatcode/e/raw/main/zwerve.exe",
            "https://github.com/holdthatcode/e/raw/main/CBLines.exe",
            "https://github.com/holdthatcode/e/raw/main/Anch.exe"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "RLMA-2024-11028",
            "import_time": "2024-12-09T14:38:43.254660368Z",
            "modified_time": "2024-12-09T06:50:09Z",
            "sha256": "2ebefe7c01e51837216afb24515d52e8f2e3ef40950484ce03dca559e6fa1ced",
            "source": "reversing-labs",
            "versions": [
                "0.0.1"
            ]
        },
        {
            "id": "pypi/2024-08-embeds-RealtekHDAudioManager/discould",
            "import_time": "2025-12-02T22:30:55.110402943Z",
            "modified_time": "2024-09-04T21:25:32Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "4424a97d3bdb8eb365f0a7484f0f2a760c30c0cdd0c369e0a0f3e6ead9fb418e",
            "source": "kam193"
        },
        {
            "id": "pypi/2024-08-embeds-RealtekHDAudioManager/discould",
            "import_time": "2025-12-02T23:07:18.121934532Z",
            "modified_time": "2024-09-04T21:25:32Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "bb38a630a1e0c6e81089ebb95d407d438c932c26527fde69e9c304305d267ca9",
            "source": "kam193"
        },
        {
            "id": "pypi/2024-08-embeds-RealtekHDAudioManager/discould",
            "import_time": "2025-12-10T21:38:57.406605896Z",
            "modified_time": "2024-09-04T21:25:32Z",
            "sha256": "a3d9cb3ff1a1e23729c8f546a15c47ae68b5caf4fba54863827d766d5c9f438e",
            "source": "kam193",
            "versions": [
                "0.0.1"
            ]
        },
        {
            "id": "RLUA-2026-00276",
            "import_time": "2026-03-19T12:19:41.175834257Z",
            "modified_time": "2026-03-18T12:13:21Z",
            "sha256": "2cec5eb9c102e1d8661bd7004a3d0cf85f15205063e573a0d5e2325fe4df7583",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

PyPI / discould

Package

Affected ranges

Affected versions

0.*
0.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discould/MAL-2024-11578.json"