MAL-2024-12256

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discord-embedbuilder/MAL-2024-12256.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-12256
Published
2024-07-06T17:16:40Z
Modified
2025-12-31T02:53:21.303204Z
Summary
Malicious code in discord-embedbuilder (PyPI)
Details

-= Per source details. Do not edit below this line.=-

## Source: kam193 (45cebe5c70c375a3a60730db78e39aeee85af996b3982a69d6889300224d7137)

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: duvet-love-odyssey

Reasons (based on the campaign):

  • infostealer
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "2bc536d495350774426038ad895c44e3418c56624d902d4457613421e6816274",
            "import_time": "2025-12-02T22:30:54.879903972Z",
            "modified_time": "2024-07-06T17:16:40Z",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "id": "pypi/duvet-love-odyssey/Discord-EmbedBuilder",
            "source": "kam193"
        },
        {
            "sha256": "75ca2b2f56c1a7686f7411d019530b45e374f5aff495e6ca38cf53f7d960ddde",
            "import_time": "2025-12-02T22:30:55.103165567Z",
            "modified_time": "2024-07-06T17:16:40Z",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "id": "pypi/duvet-love-odyssey/discord-embedbuilder",
            "source": "kam193"
        },
        {
            "sha256": "45cebe5c70c375a3a60730db78e39aeee85af996b3982a69d6889300224d7137",
            "import_time": "2025-12-02T23:07:18.114558017Z",
            "modified_time": "2024-07-06T17:16:40Z",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "id": "pypi/duvet-love-odyssey/discord-embedbuilder",
            "source": "kam193"
        },
        {
            "sha256": "5c88286ad87831eec59c9e1cbaadbdd49832574230b8abc53249bf092a3c3f51",
            "import_time": "2025-12-02T23:07:17.922217535Z",
            "modified_time": "2024-07-06T17:16:40Z",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "id": "pypi/duvet-love-odyssey/Discord-EmbedBuilder",
            "source": "kam193"
        },
        {
            "sha256": "a0fd33ddaa4a655d198cf24b649e8d23576e7483e600495a8d894c0c948e868e",
            "import_time": "2025-12-10T21:38:57.400004039Z",
            "modified_time": "2024-07-06T17:16:40Z",
            "versions": [
                "2.5.4",
                "2.5.5",
                "2.5.3",
                "2.5.6"
            ],
            "id": "pypi/duvet-love-odyssey/discord-embedbuilder",
            "source": "kam193"
        },
        {
            "sha256": "99366e271ecadfe7796ffb0f28abad9f3c79685f831f71eaf4ca32f9b2ee07d5",
            "import_time": "2025-12-30T22:39:04.071560646Z",
            "modified_time": "2024-07-06T17:16:40Z",
            "versions": [
                "2.5.3",
                "2.5.4",
                "2.5.5",
                "2.5.6"
            ],
            "id": "pypi/duvet-love-odyssey/discord-embedbuilder",
            "source": "kam193"
        }
    ]
}
References
Credits

Affected packages

PyPI / discord-embedbuilder

Package

Name
discord-embedbuilder
View open source insights on deps.dev
Purl
pkg:pypi/discord-embedbuilder

Affected ranges

Affected versions

2.*
2.5.3
2.5.4
2.5.5
2.5.6

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discord-embedbuilder/MAL-2024-12256.json"