{"id":"MAL-2026-5345","title":"Malicious code in dstill (PyPI)","summary":"Malicious code in dstill (PyPI)","severity":"none","vendor":"dstill","product":"dstill","ecosystem":"pip","affected":["dstill"],"published":"2026-06-09","updated":"2026-07-24","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-5345","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/dstill"},{"url":"https://pypi.org/project/dstill/0.3.0/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-25T19:08:10.908Z","slug":"MAL-2026-5345","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (698645f1cbbe41dbe7b65f3cf373ed38f59cb59ca9cc0bb25bd9d175114f1762)\nOn `import spaysdata`, __init__.py invokes main_entry() which executes a multi-stage Windows infostealer with no relation to the package's advertised purpose (a 'Roblox DataStore' library). Behaviors: (1) reads %USERPROFILE%\\AppData\\Local\\Roblox\\LocalStorage\\robloxcookies.dat, decrypts via CryptUnprotectData, and POSTs the plaintext cookies to a hardcoded Discord webhook (discord.com/api/webhooks/1513807955340820602/...) and a Google Apps Script endpoint (script.google.com/macros/s/AKfycbwa8sLEdsG_leFVecuc.../exec); (2) kills Discord processes via `taskkill /f /im Discord.exe`, then enumerates Discord/Discord Canary/PTB/Lightcord and ~20 Chromium browsers (Chrome, Edge, Brave, Yandex, Opera, Vivaldi,...) plus Firefox profiles, AES-GCM-decrypts tokens with each browser's DPAPI master key, validates them against the Discord API, and exfiltrates working tokens to the same endpoints; (3) installs persistence by copying itself to %LOCALAPPDATA%\\MicrosoftSecurityWorker\\WindowsSecurity.{pyw,exe}, registers that directory as a Windows Defender ExclusionPath via PowerShell `Add-MpPreference`, and creates a `schtasks /sc onlogon /rl highest` task named 'WindowsSecurityUpdate' to run at every logon. The Microsoft-lookalike paths/names are explicit AV evasion. Russian/Ukrainian comments in the source acknowledge the stealth and anti-AV intent. The pyproject description in Russian ('Библиотека для работы с DataStore в Roblox') is a lure targeting Roblox developers.\n\n## Source: kam193 (09fdc0fbdc8b1ba29a63f2807ec9c9af6dd1079a5ac6fa99c88b54df9bd22a0b)\nThe package exfiltrates Roblox cookies from the victim machine.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-spaysrbdata\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n## Affected packages\n\n- `dstill`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}