MAL-2026-10701

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discord-telemetry/MAL-2026-10701.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10701
Published
2026-07-16T14:12:05Z
Modified
2026-08-05T07:21:40Z
Summary
Malicious code in discord-telemetry (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (225e2e6a53c221447d09b6259d38d079c519056851186eb72405cb2904072c0b)

No a static rule matches or traced code paths indicate exfiltration, install-time code execution, credential theft, silent-relay, backdoor, or self-propagation behavior in this package version. The package name references 'discord' and 'telemetry', but a name alone is not a supply-chain threat and this version's contents do not exhibit any of the fingerprints (browser credential-store enumeration, Discord leveldb session theft, hardcoded C2 endpoint, install-time fetch-and-execute) that would justify escalation.

Source: kam193 (b8a926675ed9f43b0067def4bd625208d08a08c8750fd3c2f9f7bfd6138e3d4d)

During installation, the package downloads and executes a remote executable. Before 0.1.5, the code contained local-only tests of malicious behaviour.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-discord-telemetry

Reasons (based on the campaign):

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • Downloads and executes a remote executable.

  • malware

Database specific
{
    "iocs": {
        "domains": [
            "gaming-telemetry.com"
        ],
        "urls": [
            "https://gaming-telemetry.com/v1/beaconafter",
            "https://gaming-telemetry.com/v1/download"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "pypi/2026-07-discord-telemetry/discord-telemetry",
            "import_time": "2026-07-16T14:43:45.227465231Z",
            "modified_time": "2026-07-16T14:12:05.940988Z",
            "sha256": "b8a926675ed9f43b0067def4bd625208d08a08c8750fd3c2f9f7bfd6138e3d4d",
            "source": "kam193",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2",
                "0.1.3",
                "0.1.4",
                "0.1.5"
            ]
        },
        {
            "id": "IN-MAL-2026-013311",
            "import_time": "2026-08-05T07:06:40.788672012Z",
            "modified_time": "2026-08-05T06:05:01Z",
            "sha256": "1bc82ff7d282075bebc715bfa3671b1b1501752fd1d9acc8227f0a7ac45b1aac",
            "source": "amazon-inspector",
            "versions": [
                "0.1.3"
            ]
        },
        {
            "id": "IN-MAL-2026-013314",
            "import_time": "2026-08-05T07:06:40.950072357Z",
            "modified_time": "2026-08-05T06:05:27Z",
            "sha256": "225e2e6a53c221447d09b6259d38d079c519056851186eb72405cb2904072c0b",
            "source": "amazon-inspector",
            "versions": [
                "0.1.0"
            ]
        },
        {
            "id": "IN-MAL-2026-013310",
            "import_time": "2026-08-05T07:06:40.743713703Z",
            "modified_time": "2026-08-05T06:04:55Z",
            "sha256": "3841906767dc86fa36819ed8d5b85af1f831ea0284f5a51da6ca25f8069be30e",
            "source": "amazon-inspector",
            "versions": [
                "0.1.2"
            ]
        },
        {
            "id": "IN-MAL-2026-013313",
            "import_time": "2026-08-05T07:06:40.894856935Z",
            "modified_time": "2026-08-05T06:05:17Z",
            "sha256": "b6e8738505f6ba76bfb0d93b9f9f5eb2ea95fdf5fd8cfe4e4cbe6a6b1e4fc023",
            "source": "amazon-inspector",
            "versions": [
                "0.1.1"
            ]
        },
        {
            "id": "IN-MAL-2026-013312",
            "import_time": "2026-08-05T07:06:40.835615734Z",
            "modified_time": "2026-08-05T06:05:08Z",
            "sha256": "f97417f974a7b0ca7ee05e859354c3aca4d26c656773cc494e09be027b1e8449",
            "source": "amazon-inspector",
            "versions": [
                "0.1.4"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / discord-telemetry

Package

Name
discord-telemetry
View open source insights on deps.dev
Purl
pkg:pypi/discord-telemetry

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "discord_telemetry-0.1.3.tar.gz",
            "hashes": {
                "blake2b_256": "0aa49c33ad2f8e2f984eb48ad4d78b1dc4e558555c24205cb3ee974d995d3797",
                "md5": "c96680627128317fe27b42657736a0ad",
                "sha256": "98d2b5e629641a5c55c9d5879ebae87254da063a6d712a575a6420925b6f8fd8"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discord-telemetry/MAL-2026-10701.json"