---
id: MAL-2026-5329
title: Malicious code in spaysdatarbx (PyPI)
summary: Malicious code in spaysdatarbx (PyPI)
severity: none
vendor: spaysdatarbx
product: spaysdatarbx
ecosystem: pip
affected:
  - spaysdatarbx
published: '2026-06-08'
updated: '2026-07-24'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-5329'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/spaysdatarbx'
  - url: 'https://pypi.org/project/spaysdatarbx/0.1.5/'
  - url: 'https://pypi.org/project/spaysdatarbx/0.1.3/'
tags:
  - osv
  - pip
ingestedAt: '2026-07-25T19:08:10.859Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1bcaa4bf6f81efed82d35081ec059dfcd2f55e50b84f28d8b0ad4d8afe63089f)
spaysdatarbx is a Windows infostealer disguised as a Roblox DataStore library. On `import spaysdata`, __init__.py invokes main_entry() (wrapped in try/except: pass to stay silent), which performs three malicious actions: (1) reads %USERPROFILE%/AppData/Local/Roblox/LocalStorage/robloxcookies.dat, DPAPI-decrypts it, and POSTs the plaintext Roblox session cookie to a hardcoded Discord webhook (https://discord.com/api/webhooks/1499336276762038292/...); (2) walks Discord, Chrome, Edge, Brave, Opera, Yandex, and Firefox profile directories, force-kills Discord with `taskkill /f /im Discord.exe` to release leveldb locks, AES-GCM-decrypts auth tokens with each browser's DPAPI master key, and POSTs every recovered token to the same webhook; (3) establishes persistence by copying itself to %APPDATA%\MySystemUtility\ and writing an HKCU\...\Run\MyPythonAutostartApp registry value that re-launches the stealer at every login, hiding the console window via ShowWindow(GetConsoleWindow(), 0). The package's advertised purpose ('Библиотека для работы с DataStore в Roblox') is a decoy — no DataStore functionality exists in main.py, only the stealer. Any developer who installs and imports this package has their Roblox session and all browser-stored Discord tokens sent to the attacker, plus a persistent autostart entry for ongoing theft.

## Source: kam193 (31b0b97326861aabb747f26e130a5dbda5ac78100fafbb3a3327b1981119e3a6)
The package exfiltrates Roblox cookies from the victim machine.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-spaysrbdata


Reasons (based on the campaign):


 - infostealer


## Affected packages

- `spaysdatarbx`

## Remediation

Refer to the advisory for the patched release.
