-= Per source details. Do not edit below this line.=-
Package suggests a code to build bots; however, the code just exfiltrates the token given by the user to the hardcoded Discord webhook. Looking at other activity on the account, it's either research or forgotten WIP/test.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2024-09-old-discself
Reasons (based on the campaign):
action-hidden-in-lib-usage
-
{
"malicious-packages-origins": [
{
"sha256": "da6f874baf1f1b19d25ce956179469d4c78f72c1e64b1cfa336db9e543c7be8c",
"source": "kam193",
"modified_time": "2024-09-16T19:59:03Z",
"id": "pypi/2024-09-old-discself/discself",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.996591276Z"
},
{
"sha256": "271e2fef9fd10cd1a179df1be1e1f92c837d1ecf3d074451a9b1b6205babe511",
"source": "kam193",
"modified_time": "2024-09-16T19:59:03Z",
"id": "pypi/2024-09-old-discself/discself",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:19.191433413Z"
},
{
"sha256": "b632964703138c2175e285be4e1f91611d3bb6c86b8eba814c94265021b56486",
"source": "kam193",
"modified_time": "2024-09-16T19:59:03Z",
"id": "pypi/2024-09-old-discself/discself",
"versions": [
"1.0.0"
],
"import_time": "2025-12-10T21:38:58.332817544Z"
}
],
"iocs": {
"urls": [
"https://discord.com/api/webhooks/912467064164323348/5wRkOV95qAwWdY4KBmbO9-3d2tf4FrSE4R2i7LWGyzfEevzi0xvKaJmLo-Z_AN0OFqGh"
]
}
}