Cybersecurity researchers have uncovered a coordinated campaign in which malicious packages distributed through popular open-source repositories—npm, PyPI, and RubyGems—are being used to exfiltrate sensitive developer data using Discord webhooks as a command-and-control (C2) channel. Attackers have published several packages, such as mysql-dumpdiscord and nodejs.discord on npm, as well as malinssx, malicus, and maliinn on PyPI, and sqlcommenter_rails on RubyGems, which are designed to steal configuration files, environment variables, and host information from developer systems. These packages leverage Discord webhooks, which allow data to be sent directly to attacker-controlled Discord channels without requiring authentication or bot users, making detection and mitigation more challenging. The use of Discord webhooks is particularly insidious because webhook URLs are write-only, preventing defenders from easily auditing what data has been exfiltrated. In some cases, the malicious code is triggered during package installation, such as with 'pip install' commands, enabling the theft of sensitive information before runtime monitoring can detect the activity. The stolen data includes critical files like config.json, .env, ayarlar.js, ayarlar.json, and even system files such as '/etc/passwd' and '/etc/resolv.conf', which may contain credentials, API keys, and other secrets. By abusing Discord’s infrastructure, attackers avoid the costs and risks associated with maintaining their own C2 servers, and their traffic often blends in with legitimate communications, bypassing many firewall and monitoring solutions. The campaign highlights the ongoing risks associated with software supply chain attacks, where threat actors target developers and CI/CD environments by injecting malicious code into widely used open-source packages. Security experts warn that such attacks can have far-reaching consequences, as compromised developer machines and build systems may inadvertently propagate stolen secrets or further malicious code into downstream applications. The discovery underscores the importance of rigorous package vetting, monitoring for suspicious network activity, and the use of security tools that can detect anomalous behavior during package installation. Researchers emphasize that the abuse of Discord webhooks for C2 is a growing trend, as it offers attackers a free, scalable, and stealthy method for data exfiltration. The incident serves as a reminder for organizations to review their dependency management practices and to educate developers about the risks of installing untrusted packages. The affected repositories have been notified, and some of the malicious packages have been removed, but the ease of publishing new packages means the threat remains ongoing. This campaign demonstrates the evolving tactics of threat actors in targeting the software supply chain and the need for continuous vigilance in the open-source ecosystem. Organizations are advised to implement automated scanning of dependencies and to restrict outbound network connections from build environments where possible. The use of Discord as a C2 channel is expected to persist, given its accessibility and the difficulty of monitoring webhook-based exfiltration. Security teams should update detection rules to flag unexpected communications with Discord domains, especially from development and CI/CD systems. The incident also highlights the broader challenge of securing open-source software, where trust in package maintainers and repositories is critical but increasingly under attack.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers also reported that the North Korean-linked 'Contagious Interview' campaign had seeded 338 malicious npm packages targeting Web3, cryptocurrency, and blockchain developers. The packages, downloaded more than 50,000 times, were used to deliver BeaverTail and InvisibleFerret malware and harvest credentials and wallet data.
Security researchers discovered multiple malicious packages across npm, PyPI, and RubyGems that used Discord webhooks as command-and-control channels to steal developer data, including configuration files, host information, and credentials. Reported package examples included mysql-dumpdiscord, malinssx, and sqlcommenter_rails.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.