logo

Malicious PyPi package steals Discord auth tokens from devs

ID: e800f6e3-6a18-5592-a059-90c09887ea64

STIX ID: report--e800f6e3-6a18-5592-a059-90c09887ea64

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-17

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

**Malicious PyPI package 'pycord-self' impersonating 'discord.py-self' was uploaded to PyPI and, according to researchers, has been downloaded ~885 times; it steals Discord authentication tokens and establishes a persistent remote backdoor (remote shell on port 6969) allowing account hijack and ongoing system access.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.