-= Per source details. Do not edit below this line.=-
setup.py contains a base64-encoded shell command that decodes to a curl fetch of an opaque binary from https://gaming-telemetry.com/v1/download, chmods it executable, and runs it. The payload invocation _run_payload("module") is called at top-level module scope and is additionally wired into CustomInstall, CustomBuildPy, and CustomDevelop cmdclasses so it fires on any pip install, build, or develop path. The fetch destination is not a publisher-owned domain, the fetched bytes are not pinned or hash-verified, and the shell command is deliberately hidden behind base64 encoding. Installing this package hands remote code execution on the installer's machine to whoever controls gaming-telemetry.com.
During installation, the package downloads and executes a remote executable. Before 0.1.5, the code contained local-only tests of malicious behaviour.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-discord-telemetry
Reasons (based on the campaign):
The package overrides the install command in setup.py to execute malicious code during installation.
Downloads and executes a remote executable.
malware
{
"iocs": {
"domains": [
"gaming-telemetry.com"
],
"urls": [
"https://gaming-telemetry.com/v1/beaconafter",
"https://gaming-telemetry.com/v1/download"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-07-discord-telemetry/discordia-telemetria",
"import_time": "2026-07-16T17:32:38.467456057Z",
"modified_time": "2026-07-16T16:25:06.946232Z",
"sha256": "ab73f38fc09955a1adcf493615ca1b8d6f3dedb2ae53d232c4c52b9aee9d26ee",
"source": "kam193",
"versions": [
"0.1.1",
"0.1.2"
]
},
{
"id": "IN-MAL-2026-010938",
"import_time": "2026-07-28T14:20:00.103123613Z",
"modified_time": "2026-07-28T13:39:08Z",
"sha256": "d7b7d95c58f4a5203f542a11bc6e8ea0ff4d55bf22b2db938b563f169a732265",
"source": "amazon-inspector",
"versions": [
"0.1.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "setup.py",
"sha256": "68eca2263970b775c24801ac5c2f6e3f35bbe84a795e40bd50588e809fdd515d",
"tlsh": "f4117d25c13720784ac50ab045d78ea1ceb37f177e40abd939fe26544f5b031d419097"
}
],
"package_integrity": [
{
"filename": "discordia_telemetria-0.1.1.tar.gz",
"hashes": {
"blake2b_256": "b93b1f80f37f4d25136b21b0b04974a31bea3649f9612d4013adce0a658855e1",
"md5": "d474e956129013107aed897113665d6a",
"sha256": "0b77c1367cfe86b8ccaeadb4ec5aab49e2efca06d54e99c89117e520b2434fbd"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/discordia-telemetria/MAL-2026-10702.json"