MAL-2026-5329Malicious code in spaysdatarbx (PyPI)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
0.1.3 | unavailable | — | — | — |
0.1.5 | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| PyPI | spaysdatarbx | 0.1.3 |
| PyPI | spaysdatarbx | 0.1.5 |
{"schema_version":"1.7.4","id":"MAL-2026-5329","published":"2026-06-08T13:43:18Z","modified":"2026-08-27T13:38:48.299645460Z","summary":"Malicious code in spaysdatarbx (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1bcaa4bf6f81efed82d35081ec059dfcd2f55e50b84f28d8b0ad4d8afe63089f)\nspaysdatarbx is a Windows infostealer disguised as a Roblox DataStore library. On `import spaysdata`, __init__.py invokes main_entry() (wrapped in try/except: pass to stay silent), which performs three malicious actions: (1) reads %USERPROFILE%/AppData/Local/Roblox/LocalStorage/robloxcookies.dat, DPAPI-decrypts it, and POSTs the plaintext Roblox session cookie to a hardcoded Discord webhook (https://discord.com/api/webhooks/1499336276762038292/...); (2) walks Discord, Chrome, Edge, Brave, Opera, Yandex, and Firefox profile directories, force-kills Discord with `taskkill /f /im Discord.exe` to release leveldb locks, AES-GCM-decrypts auth tokens with each browser's DPAPI master key, and POSTs every recovered token to the same webhook; (3) establishes persistence by copying itself to %APPDATA%\\MySystemUtility\\ and writing an HKCU\\...\\Run\\MyPythonAutostartApp registry value that re-launches the stealer at every login, hiding the console window via ShowWindow(GetConsoleWindow(), 0). The package's advertised purpose ('Библиотека для работы с DataStore в Roblox') is a decoy — no DataStore functionality exists in main.py, only the stealer. Any developer who installs and imports this package has their Roblox session and all browser-stored Discord tokens sent to the attacker, plus a persistent autostart entry for ongoing theft.\n\n## Source: kam193 (31b0b97326861aabb747f26e130a5dbda5ac78100fafbb3a3327b1981119e3a6)\nThe package exfiltrates Roblox cookies from the victim machine.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-spaysrbdata\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n","affected":[{"package":{"name":"spaysdatarbx","ecosystem":"PyPI"},"versions":["0.1.3","0.1.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"spaysdata/main.py","sha256":"77e2aaa0ecbba755c48dc5987789afbe7432d406d6db3b1d66d2615e1694db79","tlsh":"2a324342ec4a14169276925ca852ed08f72743ab757122033efca7a83f75035e3b91fe"},{"path":"PKG-INFO","sha256":"ab5f0d915d70f36c0460833a78315361157da0381e0ebbfa204ee46476243fca","tlsh":"a2e068a05b927430a2f899cf842c8b1aae6ae700649e04fae6845c6d12e3390467833c"}],"package_integrity":[{"filename":"spaysdatarbx-0.1.5-py3-none-any.whl","hashes":{"blake2b_256":"b7b23361edab7b2256a2206a52c01b39dfdc0f808fe1390e98f3a8c1b38fe7fe","md5":"a35057fc2aea54a3a7c41010ee6d86b9","sha256":"d198fdb35f9a8e20a99134ff07827874795b9c59197cce7472192693be2a68cb"}},{"filename":"spaysdatarbx-0.1.5.tar.gz","hashes":{"blake2b_256":"560694d1f8f5a76ebe810125e6e9b23f1b8d2d132b368fc424b71cc2ed520ab3","md5":"a5a9794be974348f8e67d6b0118eac4f","sha256":"23016a21246d121e1e522308d2827515a01ce91d4ad007e4c7d8d60f8fa7bc54"}}]}}}],"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/spaysdatarbx"},{"type":"PACKAGE","url":"https://pypi.org/project/spaysdatarbx/0.1.5/"},{"type":"PACKAGE","url":"https://pypi.org/project/spaysdatarbx/0.1.3/"}],"database_specific":{"iocs":{"urls":["https://script.google.com/macros/s/AKfycbwa8sLEdsG_leFVecuc_dFrZ_h5JnZKrWxXWazK1T6DoKGAGG5OJ9rznwYXg2PS-h1d/exec","https://discord.com/api/webhooks/1513807955340820602/-UbLOjMGWIop17hrvQ7XsrZkJBJaNlMTueX7xnsJ9hz6DKaBgSe_Ur2FIgSJMHlusBwx"]},"malicious-packages-origins":[{"id":"pypi/2026-06-spaysrbdata/spaysdatarbx","import_time":"2026-06-08T15:12:45.407175189Z","modified_time":"2026-06-08T13:43:18.338578Z","sha256":"31b0b97326861aabb747f26e130a5dbda5ac78100fafbb3a3327b1981119e3a6","source":"kam193","versions":["0.1.3","0.1.5"]},{"id":"pypi/2026-06-spaysrbdata/spaysdatarbx","import_time":"2026-06-09T10:41:59.933480846Z","modified_time":"2026-06-08T13:43:18.338578Z","sha256":"ddffc9e3413a0002eb53a77c72679297563add6c776b89475e9e0bb83d516d49","source":"kam193","versions":["0.1.3","0.1.5"]},{"id":"IN-MAL-2026-005401","import_time":"2026-06-11T03:48:46.730517847Z","modified_time":"2026-06-11T02:54:32Z","sha256":"1bcaa4bf6f81efed82d35081ec059dfcd2f55e50b84f28d8b0ad4d8afe63089f","source":"amazon-inspector","versions":["0.1.5"]},{"id":"IN-MAL-2026-005402","import_time":"2026-06-11T03:48:46.83398529Z","modified_time":"2026-06-11T02:54:36Z","sha256":"28acb1db885e57d4a1f6f5bcdfb316141626b89be210c550654266524d23acc7","source":"amazon-inspector","versions":["0.1.3"]},{"id":"pypi/2026-06-spaysrbdata/spaysdatarbx","import_time":"2026-07-24T20:00:55.340648129Z","modified_time":"2026-06-08T13:43:18.338578Z","sha256":"a00fa386bd2921286903f63dd50f713af260c3b12586ee801b2f17fb5e85031f","source":"kam193","versions":["0.1.3","0.1.5"]},{"id":"pypi/2026-06-spaysrbdata/spaysdatarbx","import_time":"2026-08-27T13:37:01.772133222Z","modified_time":"2026-06-08T13:43:18.338578Z","sha256":"bfe7e38c672b3e342c23ac10385155fa466f7e13ae9138958e5b3e2a22f65736","source":"kam193","versions":["0.1.3","0.1.5"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0