• News/
  • https://www.bleepingcomputer.com/news/security/hackers-poison-source-code-from-largest-discord-bot-platform/

Hackers poison source code from largest Discord bot platform

BleepingComputer
·
Bill Toulas
·
Published Mar 25, 2024
·
Updated

The Top.gg Discord bot community with over 170,000 members has been impacted by a supply-chain attack aiming to infect developers with malware that steals sensitive information. The threat actor has been using several tactics, techniques, and procedures (TTPs) over the years, including hijacking GitHub accounts, distributing malicious Python packages, using a fake Python infrastructure, and social engineering. One of the more recent victims of the attacker is Top.gg, a popular search-and-discovery platform for Discord servers, bots, and other social tools geared towards gaming, boosting engagement, and improving functionality. Checkmarx researchers discovered the campaign and note that the main goal was most likely data theft and monetization through selling the stolen info. According to the researchers, the attacker's activity started back in November 2022, when they first uploaded malicious packages on the Python Package Index (PyPI). In the years that followed, more packages carrying malware were uploaded to PyPI. These resembled popular open-source tools with enticing descriptions that would make them more likely to rank well in search engine results. The most recent upload was a package named "yocolor" in March this year. In early 2024, the attackers set up a fake Python package mirror at "files[.]pypihosted[.]org," which is a typosquatting attempt to mimic the authentic "files.pythonhosted.org" where the artifact files of PyPI packages are stored. This fake mirror was ...

Read full article

Affected Software

5 affected components
Python Python Package Index (PyPI)
Python colorama
Python yocolor
Discord Top.gg
GitHub Repository
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a supply-chain attack that has contaminated the source code of the largest Discord bot platform, Top.gg.

2

What security implications are discussed?

The attack aims to infect developers with malware designed to steal sensitive information.

3

What products or software are affected?

The affected software includes the Top.gg platform, Python Package Index (PyPI), colorama, yocolor, and GitHub repositories.

4

How many users are part of the affected Discord community?

The Top.gg Discord bot community has over 170,000 members.

5

What tactics are being used by the threat actors?

The threat actors are employing several tactics and techniques to carry out the supply-chain attack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203