MAL-2026-11503

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/instalogin1234/MAL-2026-11503.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11503
Published
2026-08-03T20:34:47Z
Modified
2026-08-04T22:05:26.021875566Z
Summary
Malicious code in instalogin1234 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4c7d01985e4b5c4afe1e4aafc0eb9a3d97feb1eacae68ef70adf962846392460)

The package presents itself as a 'Modern Instagram CLI' but its login command displays a fake Instagram login prompt that reads a username and password via input() and POSTs the concatenated credentials to a hardcoded Discord channel (channel id 1246456414843437101) using a hardcoded Discord bot authorization token embedded in shell.py. After exfiltration it opens https://instagram.com/ in the user's browser as cover so the interaction appears to succeed. The advertised purpose is a cover story for credential harvesting; the Discord channel and bot token are attacker-controlled.

Source: kam193 (f6ed64b38b3e872668e1d36a02c53136da1ab70ec9dacd2ac3b7d38c31794ebe)

The package promises to be an Instagram CLI and offers "login". Entered credentials are sent to a Discord channel, and the user is presented with the Instagram website just opened in the browser.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-instalogin1234

Reasons (based on the campaign):

  • exfiltration-credentials
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-08-03T20:34:47.160662Z",
            "source": "kam193",
            "sha256": "f6ed64b38b3e872668e1d36a02c53136da1ab70ec9dacd2ac3b7d38c31794ebe",
            "import_time": "2026-08-03T20:52:49.256603933Z",
            "id": "pypi/2026-08-instalogin1234/instalogin1234",
            "versions": [
                "0.0.1"
            ]
        },
        {
            "source": "amazon-inspector",
            "import_time": "2026-08-04T21:33:13.0913301Z",
            "sha256": "4c7d01985e4b5c4afe1e4aafc0eb9a3d97feb1eacae68ef70adf962846392460",
            "modified_time": "2026-08-04T21:18:04Z",
            "id": "IN-MAL-2026-011002",
            "versions": [
                "0.0.1"
            ]
        }
    ],
    "iocs": {
        "urls": [
            "https://discord.com/api/v9/channels/1246456414843437101/messages"
        ]
    }
}
References
Credits

Affected packages

PyPI / instalogin1234

Package

Affected ranges

Affected versions

0.*
0.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "instalogin1234-0.0.1-py3-none-any.whl",
            "hashes": {
                "md5": "deac6bd35f16246fcf4e138c4ae0ed26",
                "blake2b_256": "1ffbb59b80fa91689d01dc0dea6d5960ea2566ff89cb7c29ace94fe7da03041d",
                "sha256": "21431541485d6efd5f012502856311aa3a08fa10294a0ba1326b4a86299ce177"
            }
        },
        {
            "filename": "instalogin1234-0.0.1.tar.gz",
            "hashes": {
                "md5": "0ac3eb7cbdc5b53850ed1e9c7082c22b",
                "blake2b_256": "3113326a0cf977ca33b69c7393f4732402b6da7e8fa82697aa5cf295d5fbbc90",
                "sha256": "fdd4bbaccd1004f29e1822fb5cdc05b5f07541b641a62babadee31d89d6925c0"
            }
        }
    ],
    "evidence_files": [
        {
            "tlsh": "735134229db65472227aca1ce8178021fa4637173ab8b52f7a2ca63c4ff885491524fd",
            "sha256": "8f51f1e171a54506697273ee24209e60720f4a9e0b9eae3c75731854f9ec87ff",
            "path": "instalogin/shell.py"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/instalogin1234/MAL-2026-11503.json"