VYPR

pypi · Malicious package advisory

Malware

noteasonfnsource

MAL-2026-1098

Malicious code in noteasonfnsource (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (fa2242ec1849ffa55a55c85b7781623cdc7147b8568b3beaa5d2b3b956c04e17)
Code provides a Discord bot, which - once a generic command is called - performs malicious action against the Discord server: deletes all channels, renames the server, and then starts a loop that creates spamming channels and notifies everyone.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-02-old-noteasonfnsource


Reasons (based on the campaign):


 - abusing-3rd-api


 - other

Compromised versions (1)

  • 1.0.3

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.