-= Per source details. Do not edit below this line.=-
No a static rule matches or traced code paths indicate exfiltration, install-time code execution, credential theft, silent-relay, backdoor, or self-propagation behavior in this package version. The package name references 'discord' and 'telemetry', but a name alone is not a supply-chain threat and this version's contents do not exhibit any of the fingerprints (browser credential-store enumeration, Discord leveldb session theft, hardcoded C2 endpoint, install-time fetch-and-execute) that would justify escalation.
During installation, the package downloads and executes a remote executable. Before 0.1.5, the code contained local-only tests of malicious behaviour.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-discord-telemetry
Reasons (based on the campaign):
The package overrides the install command in setup.py to execute malicious code during installation.
Downloads and executes a remote executable.
malware
{
"iocs": {
"domains": [
"gaming-telemetry.com"
],
"urls": [
"https://gaming-telemetry.com/v1/beaconafter",
"https://gaming-telemetry.com/v1/download"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-07-discord-telemetry/discord-telemetry",
"import_time": "2026-07-16T14:43:45.227465231Z",
"modified_time": "2026-07-16T14:12:05.940988Z",
"sha256": "b8a926675ed9f43b0067def4bd625208d08a08c8750fd3c2f9f7bfd6138e3d4d",
"source": "kam193",
"versions": [
"0.1.0",
"0.1.1",
"0.1.2",
"0.1.3",
"0.1.4",
"0.1.5"
]
},
{
"id": "IN-MAL-2026-013311",
"import_time": "2026-08-05T07:06:40.788672012Z",
"modified_time": "2026-08-05T06:05:01Z",
"sha256": "1bc82ff7d282075bebc715bfa3671b1b1501752fd1d9acc8227f0a7ac45b1aac",
"source": "amazon-inspector",
"versions": [
"0.1.3"
]
},
{
"id": "IN-MAL-2026-013314",
"import_time": "2026-08-05T07:06:40.950072357Z",
"modified_time": "2026-08-05T06:05:27Z",
"sha256": "225e2e6a53c221447d09b6259d38d079c519056851186eb72405cb2904072c0b",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
},
{
"id": "IN-MAL-2026-013310",
"import_time": "2026-08-05T07:06:40.743713703Z",
"modified_time": "2026-08-05T06:04:55Z",
"sha256": "3841906767dc86fa36819ed8d5b85af1f831ea0284f5a51da6ca25f8069be30e",
"source": "amazon-inspector",
"versions": [
"0.1.2"
]
},
{
"id": "IN-MAL-2026-013313",
"import_time": "2026-08-05T07:06:40.894856935Z",
"modified_time": "2026-08-05T06:05:17Z",
"sha256": "b6e8738505f6ba76bfb0d93b9f9f5eb2ea95fdf5fd8cfe4e4cbe6a6b1e4fc023",
"source": "amazon-inspector",
"versions": [
"0.1.1"
]
},
{
"id": "IN-MAL-2026-013312",
"import_time": "2026-08-05T07:06:40.835615734Z",
"modified_time": "2026-08-05T06:05:08Z",
"sha256": "f97417f974a7b0ca7ee05e859354c3aca4d26c656773cc494e09be027b1e8449",
"source": "amazon-inspector",
"versions": [
"0.1.4"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"package_integrity": [
{
"filename": "discord_telemetry-0.1.3.tar.gz",
"hashes": {
"blake2b_256": "0aa49c33ad2f8e2f984eb48ad4d78b1dc4e558555c24205cb3ee974d995d3797",
"md5": "c96680627128317fe27b42657736a0ad",
"sha256": "98d2b5e629641a5c55c9d5879ebae87254da063a6d712a575a6420925b6f8fd8"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discord-telemetry/MAL-2026-10701.json"