Skip to main content

Malicious code in pylever (PyPI)

0
High
Published: 09/10/2026 (09/10/2026, 06:17:45 UTC)
Source: GCVE Database
Product: pylever

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6720ca3891de59548dfdfc9b6af778b5bf97fb31c5188381c73e92c4ac2820e1) The package's `_Client` class scans Chrome, Edge, and Brave browser profile LevelDB and Cache directories and the Discord Desktop app's Roaming/discord Local Storage/leveldb for strings matching the Discord token regexes `[MN][A-Za-z0-9_-]{71}` and `mfa\.[...]{84}`, decrypts protected values via DPAPI invoked through PowerShell, validates each candidate against the Discord API, and POSTs valid tokens along with the associated username, id, email, verified flag, and bot flag to a hardcoded Discord webhook at `https://discord.com/api/webhooks/1547416857537945601/...`. `_DataFinder.find_all()` additionally walks the caller-supplied workspace path recursively and matches the same token regex against file contents, sending matches to the same webhook. The webhook URL is a module-level constant assigned in `_Client.__init__` with no API surface to override it, despite the README claiming the user configures the webhook. Package metadata uses placeholder values (`author="Your Name"`, `[email protected]`, `github.com/yourusername/pylever`) and the README frames the tool as restoring accidentally removed tokens, contradicting the actual bulk-harvest and exfiltration behavior. ## Source: kam193 (068694f49511d5a0c8678ca2196385c50cc68d1c526d5b151a6f2cdcfcae9b64) The package contains a stealer exfiltrating Discord tokens to a hardcoded location. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-pylever Reasons (based on the campaign): - infostealer

Affected software

PyPIghsa
pylever
Affected versions
=1.0.0=1.0.1=1.0.2=1.0.3=1.0.4=1.0.5=1.0.6=1.0.7=1.0.8=1.0.9=1.0.10=1.0.11=1.0.12

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 14:46:33 UTC

Technical Analysis

The pylever package versions 1.0.0 through 1.0.12 include embedded malicious code designed to steal Discord authentication tokens from infected systems and send them to a hardcoded destination. This behavior classifies the package as an infostealer with clear malicious intent. The campaign associated with this threat is identified as 2026-09-pylever. No known exploits in the wild have been reported, and no vendor advisory or patch information is available.

Potential Impact

Users who install or run affected versions of the pylever package risk having their Discord tokens stolen, which could lead to unauthorized access to their Discord accounts and potentially further compromise of related services. The malicious code exfiltrates sensitive authentication data without user consent.

Mitigation Recommendations

No official patch or remediation guidance is provided. Users should immediately discontinue use of the pylever package versions 1.0.0 through 1.0.12. It is recommended to remove the package from all environments and avoid installing or using it. Monitor for unauthorized Discord account activity and consider resetting tokens or credentials if compromise is suspected.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-16122
Osv Schema Version
1.7.4
Ecosystems
["PyPI"]

Threat ID: 6aa2af88acd9273b4925b4cd

Added to database: 09/10/2026, 13:24:24 UTC

Last enriched: 09/10/2026, 14:46:33 UTC

Last updated: 09/11/2026, 16:04:41 UTC

Views: 23

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses