-= Per source details. Do not edit below this line.=-
When used, the package silently loads code with an infostealer focused on Discord data.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-04-moooo
Reasons (based on the campaign):
exfiltration-generic
exfiltration-credentials
infostealer
action-hidden-in-lib-usage
{
"iocs": {
"urls": [
"https://discord.com/api/webhooks/1389881818181926932/S-908aALR9RjCF95UjeQ0DnqxlK_iXu6DdeMyqbzUKkSgmYAzKOioy3tV9oPMCqpXadC"
]
},
"malicious-packages-origins": [
{
"versions": [
"0.1.0",
"0.1.1"
],
"modified_time": "2026-04-14T15:21:49.651577Z",
"sha256": "110e4d99f41d1dd4567651dc21115f1793e5e2eab0e12d24ea5a433cdea87f1c",
"id": "pypi/2026-04-moooo/moooo",
"source": "kam193",
"import_time": "2026-04-14T15:31:08.692804205Z"
}
]
}