logo

Malicious PyPi package hides RAT malware, targets Discord devs since 2022

ID: fd41a919-6201-5702-8a90-5bb5fdac33df

STIX ID: report--fd41a919-6201-5702-8a90-5bb5fdac33df

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-05-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A malicious PyPI package called "discordpydebug," masquerading as a Discord bot debugging utility, was hosted on PyPI since March 2022 and downloaded over 11,000 times; once installed it behaves as a RAT that polls an attacker-controlled C2 (backstabprotection.jamesx123.repl.co) to receive commands enabling credential and file theft, remote code execution, and system monitoring, though it lacks built-in persistence or privilege escalation—developers are advised to verify package authorship and inspect third-party code before installation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.