-= Per source details. Do not edit below this line.=-
Once run, package downloads and installs an infostealer
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-11-discord-selfsbotsx
Reasons (based on the campaign):
Downloads and executes a remote executable.
infostealer
malware
peristence-autorun
{
"iocs": {
"ips": [
"212.80.7.213"
],
"urls": [
"https://pastebin.com/raw/HvFhs7zk",
"http://212.80.7.213:20578"
]
},
"malicious-packages-origins": [
{
"sha256": "1d693217182599c6434c6d03f4a857a0338b46dda49afa188000a948de42ea80",
"import_time": "2025-12-02T22:30:55.103885102Z",
"modified_time": "2025-11-27T23:24:51.238951Z",
"versions": [
"1.0.1",
"1.0.0"
],
"id": "pypi/2025-11-discord-selfsbotsx/discord-selfsbotsx",
"source": "kam193"
},
{
"sha256": "b56aa48c0654abd06a9d624b8c1b5ab4ce170399068d97b994bb4d63635bf18a",
"import_time": "2025-12-02T23:07:18.115368881Z",
"modified_time": "2025-11-27T23:24:51.238951Z",
"versions": [
"1.0.1",
"1.0.0"
],
"id": "pypi/2025-11-discord-selfsbotsx/discord-selfsbotsx",
"source": "kam193"
},
{
"sha256": "d762b62bc1e32d89da07e33977938ccf7b5868f56b22ed931b29045ae12f875e",
"import_time": "2025-12-24T10:07:30.41854501Z",
"modified_time": "2025-12-23T08:38:22Z",
"versions": [
"1.0.0"
],
"id": "RLMA-2025-06561",
"source": "reversing-labs"
},
{
"sha256": "c4c3324e23fe0fdc0ea0915c2e7c7309e7b97b02395451aceb6d5cc2a7f75241",
"import_time": "2025-12-30T22:39:04.072518703Z",
"modified_time": "2025-11-27T23:24:51.238951Z",
"versions": [
"1.0.0",
"1.0.1"
],
"id": "pypi/2025-11-discord-selfsbotsx/discord-selfsbotsx",
"source": "kam193"
},
{
"sha256": "325d188ac9a6ea235c2dd774e66e34f11ef3aa00687c289765a98e56f0d81ca8",
"import_time": "2026-03-19T12:19:40.514455902Z",
"modified_time": "2026-03-18T12:13:17Z",
"versions": [
"1.0.1"
],
"id": "RLUA-2026-00269",
"source": "reversing-labs"
}
]
}