{"id":"MAL-2026-5329","title":"Malicious code in spaysdatarbx (PyPI)","summary":"Malicious code in spaysdatarbx (PyPI)","severity":"none","vendor":"spaysdatarbx","product":"spaysdatarbx","ecosystem":"pip","affected":["spaysdatarbx"],"published":"2026-06-08","updated":"2026-07-24","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-5329","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/spaysdatarbx"},{"url":"https://pypi.org/project/spaysdatarbx/0.1.5/"},{"url":"https://pypi.org/project/spaysdatarbx/0.1.3/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-25T19:08:10.859Z","slug":"MAL-2026-5329","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1bcaa4bf6f81efed82d35081ec059dfcd2f55e50b84f28d8b0ad4d8afe63089f)\nspaysdatarbx is a Windows infostealer disguised as a Roblox DataStore library. On `import spaysdata`, __init__.py invokes main_entry() (wrapped in try/except: pass to stay silent), which performs three malicious actions: (1) reads %USERPROFILE%/AppData/Local/Roblox/LocalStorage/robloxcookies.dat, DPAPI-decrypts it, and POSTs the plaintext Roblox session cookie to a hardcoded Discord webhook (https://discord.com/api/webhooks/1499336276762038292/...); (2) walks Discord, Chrome, Edge, Brave, Opera, Yandex, and Firefox profile directories, force-kills Discord with `taskkill /f /im Discord.exe` to release leveldb locks, AES-GCM-decrypts auth tokens with each browser's DPAPI master key, and POSTs every recovered token to the same webhook; (3) establishes persistence by copying itself to %APPDATA%\\MySystemUtility\\ and writing an HKCU\\...\\Run\\MyPythonAutostartApp registry value that re-launches the stealer at every login, hiding the console window via ShowWindow(GetConsoleWindow(), 0). The package's advertised purpose ('Библиотека для работы с DataStore в Roblox') is a decoy — no DataStore functionality exists in main.py, only the stealer. Any developer who installs and imports this package has their Roblox session and all browser-stored Discord tokens sent to the attacker, plus a persistent autostart entry for ongoing theft.\n\n## Source: kam193 (31b0b97326861aabb747f26e130a5dbda5ac78100fafbb3a3327b1981119e3a6)\nThe package exfiltrates Roblox cookies from the victim machine.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-spaysrbdata\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n## Affected packages\n\n- `spaysdatarbx`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}