Malicious PyPi package hides RAT malware, targets Discord devs since 2022
ID: fd41a919-6201-5702-8a90-5bb5fdac33df
STIX ID: report--fd41a919-6201-5702-8a90-5bb5fdac33df
Feed Name: Bleeping Computer
A malicious PyPI package called "discordpydebug," masquerading as a Discord bot debugging utility, was hosted on PyPI since March 2022 and downloaded over 11,000 times; once installed it behaves as a RAT that polls an attacker-controlled C2 (backstabprotection.jamesx123.repl.co) to receive commands enabling credential and file theft, remote code execution, and system monitoring, though it lacks built-in persistence or privilege escalation—developers are advised to verify package authorship and inspect third-party code before installation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
