logo

Malicious Python Package Poses as Discord Developers to Execute Remote Commands

ID: be9ff507-2563-5b3f-8b9b-23137a72d4d0

STIX ID: report--be9ff507-2563-5b3f-8b9b-23137a72d4d0

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2025-05-09

Date Updated: 2026-04-19

Author: Mandvi

...
...

A malicious PyPI package, 'discordpydebug', masqueraded as a Discord debugging utility and operated as a remote access trojan (RAT). After installation it polled a C2 at backstabprotection.jamesx123.repl.co, allowed remote file read/write and command execution, and potentially exposed sensitive local data (configuration files, tokens, credentials); the package reached over 11,000 downloads before detection, with listed IOCs including the C2 domain and endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.