-= Per source details. Do not edit below this line.=-
The package presents itself as a 'Modern Instagram CLI' but its login command displays a fake Instagram login prompt that reads a username and password via input() and POSTs the concatenated credentials to a hardcoded Discord channel (channel id 1246456414843437101) using a hardcoded Discord bot authorization token embedded in shell.py. After exfiltration it opens https://instagram.com/ in the user's browser as cover so the interaction appears to succeed. The advertised purpose is a cover story for credential harvesting; the Discord channel and bot token are attacker-controlled.
The package promises to be an Instagram CLI and offers "login". Entered credentials are sent to a Discord channel, and the user is presented with the Instagram website just opened in the browser.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-instalogin1234
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-03T20:34:47.160662Z",
"source": "kam193",
"sha256": "f6ed64b38b3e872668e1d36a02c53136da1ab70ec9dacd2ac3b7d38c31794ebe",
"import_time": "2026-08-03T20:52:49.256603933Z",
"id": "pypi/2026-08-instalogin1234/instalogin1234",
"versions": [
"0.0.1"
]
},
{
"source": "amazon-inspector",
"import_time": "2026-08-04T21:33:13.0913301Z",
"sha256": "4c7d01985e4b5c4afe1e4aafc0eb9a3d97feb1eacae68ef70adf962846392460",
"modified_time": "2026-08-04T21:18:04Z",
"id": "IN-MAL-2026-011002",
"versions": [
"0.0.1"
]
}
],
"iocs": {
"urls": [
"https://discord.com/api/v9/channels/1246456414843437101/messages"
]
}
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"filename": "instalogin1234-0.0.1-py3-none-any.whl",
"hashes": {
"md5": "deac6bd35f16246fcf4e138c4ae0ed26",
"blake2b_256": "1ffbb59b80fa91689d01dc0dea6d5960ea2566ff89cb7c29ace94fe7da03041d",
"sha256": "21431541485d6efd5f012502856311aa3a08fa10294a0ba1326b4a86299ce177"
}
},
{
"filename": "instalogin1234-0.0.1.tar.gz",
"hashes": {
"md5": "0ac3eb7cbdc5b53850ed1e9c7082c22b",
"blake2b_256": "3113326a0cf977ca33b69c7393f4732402b6da7e8fa82697aa5cf295d5fbbc90",
"sha256": "fdd4bbaccd1004f29e1822fb5cdc05b5f07541b641a62babadee31d89d6925c0"
}
}
],
"evidence_files": [
{
"tlsh": "735134229db65472227aca1ce8178021fa4637173ab8b52f7a2ca63c4ff885491524fd",
"sha256": "8f51f1e171a54506697273ee24209e60720f4a9e0b9eae3c75731854f9ec87ff",
"path": "instalogin/shell.py"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/instalogin1234/MAL-2026-11503.json"