Malicious code in pylever (PyPI)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6720ca3891de59548dfdfc9b6af778b5bf97fb31c5188381c73e92c4ac2820e1) The package's `_Client` class scans Chrome, Edge, and Brave browser profile LevelDB and Cache directories and the Discord Desktop app's Roaming/discord Local Storage/leveldb for strings matching the Discord token regexes `[MN][A-Za-z0-9_-]{71}` and `mfa\.[...]{84}`, decrypts protected values via DPAPI invoked through PowerShell, validates each candidate against the Discord API, and POSTs valid tokens along with the associated username, id, email, verified flag, and bot flag to a hardcoded Discord webhook at `https://discord.com/api/webhooks/1547416857537945601/...`. `_DataFinder.find_all()` additionally walks the caller-supplied workspace path recursively and matches the same token regex against file contents, sending matches to the same webhook. The webhook URL is a module-level constant assigned in `_Client.__init__` with no API surface to override it, despite the README claiming the user configures the webhook. Package metadata uses placeholder values (`author="Your Name"`, `[email protected]`, `github.com/yourusername/pylever`) and the README frames the tool as restoring accidentally removed tokens, contradicting the actual bulk-harvest and exfiltration behavior. ## Source: kam193 (068694f49511d5a0c8678ca2196385c50cc68d1c526d5b151a6f2cdcfcae9b64) The package contains a stealer exfiltrating Discord tokens to a hardcoded location. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-pylever Reasons (based on the campaign): - infostealer
AI Analysis
Technical Summary
The pylever package versions 1.0.0 through 1.0.12 include embedded malicious code designed to steal Discord authentication tokens from infected systems and send them to a hardcoded destination. This behavior classifies the package as an infostealer with clear malicious intent. The campaign associated with this threat is identified as 2026-09-pylever. No known exploits in the wild have been reported, and no vendor advisory or patch information is available.
Potential Impact
Users who install or run affected versions of the pylever package risk having their Discord tokens stolen, which could lead to unauthorized access to their Discord accounts and potentially further compromise of related services. The malicious code exfiltrates sensitive authentication data without user consent.
Mitigation Recommendations
No official patch or remediation guidance is provided. Users should immediately discontinue use of the pylever package versions 1.0.0 through 1.0.12. It is recommended to remove the package from all environments and avoid installing or using it. Monitor for unauthorized Discord account activity and consider resetting tokens or credentials if compromise is suspected.
Malicious code in pylever (PyPI)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6720ca3891de59548dfdfc9b6af778b5bf97fb31c5188381c73e92c4ac2820e1) The package's `_Client` class scans Chrome, Edge, and Brave browser profile LevelDB and Cache directories and the Discord Desktop app's Roaming/discord Local Storage/leveldb for strings matching the Discord token regexes `[MN][A-Za-z0-9_-]{71}` and `mfa\.[...]{84}`, decrypts protected values via DPAPI invoked through PowerShell, validates each candidate against the Discord API, and POSTs valid tokens along with the associated username, id, email, verified flag, and bot flag to a hardcoded Discord webhook at `https://discord.com/api/webhooks/1547416857537945601/...`. `_DataFinder.find_all()` additionally walks the caller-supplied workspace path recursively and matches the same token regex against file contents, sending matches to the same webhook. The webhook URL is a module-level constant assigned in `_Client.__init__` with no API surface to override it, despite the README claiming the user configures the webhook. Package metadata uses placeholder values (`author="Your Name"`, `[email protected]`, `github.com/yourusername/pylever`) and the README frames the tool as restoring accidentally removed tokens, contradicting the actual bulk-harvest and exfiltration behavior. ## Source: kam193 (068694f49511d5a0c8678ca2196385c50cc68d1c526d5b151a6f2cdcfcae9b64) The package contains a stealer exfiltrating Discord tokens to a hardcoded location. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-pylever Reasons (based on the campaign): - infostealer
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The pylever package versions 1.0.0 through 1.0.12 include embedded malicious code designed to steal Discord authentication tokens from infected systems and send them to a hardcoded destination. This behavior classifies the package as an infostealer with clear malicious intent. The campaign associated with this threat is identified as 2026-09-pylever. No known exploits in the wild have been reported, and no vendor advisory or patch information is available.
Potential Impact
Users who install or run affected versions of the pylever package risk having their Discord tokens stolen, which could lead to unauthorized access to their Discord accounts and potentially further compromise of related services. The malicious code exfiltrates sensitive authentication data without user consent.
Mitigation Recommendations
No official patch or remediation guidance is provided. Users should immediately discontinue use of the pylever package versions 1.0.0 through 1.0.12. It is recommended to remove the package from all environments and avoid installing or using it. Monitor for unauthorized Discord account activity and consider resetting tokens or credentials if compromise is suspected.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-16122
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["PyPI"]
Threat ID: 6aa2af88acd9273b4925b4cd
Added to database: 09/10/2026, 13:24:24 UTC
Last enriched: 09/10/2026, 14:46:33 UTC
Last updated: 09/11/2026, 16:04:41 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.