A malicious Python package targeting Discord developers with remote access trojan (RAT) malware was spotted on the Python Package Index (PyPI) after more than three years. Named "discordpydebug," the package was masquerading as an error logger utility for developers working on Discord bots and was downloaded over 11,000 times since it was uploaded on March 21, 2022, even though it has no description or documentation. Cybersecurity company Socket, which first spotted it, says the malware could be used to backdoor Discord developers' systems and provide attackers with data theft and remote code execution capabilities. "The package targeted developers who build or maintain Discord bots, typically indie developers, automation engineers, or small teams who might install such tools without extensive scrutiny," Socket researchers said. "Since PyPI doesn't enforce deep security audits of uploaded packages, attackers often take advantage of this by using misleading descriptions, legitimate-sounding names, or even copying code from popular projects to appear trustworthy." Once installed, the malicious package transforms the device into a remote-controlled system that will execute instructions sent from an attacker-controlled command-and-control (C2) server. The attackers could use the malware to gain unauthorized access to credentials and more (e.g., tokens, keys, and config files), steal data and monitor system activity without being detected, remotely execute code for deploying furt...
Malicious PyPi package hides RAT malware, targets Discord devs since 2022
BleepingComputer
·Sergiu Gatlan
·Published May 8, 2025
·Updated
Affected Software
3 affected components
Python discordpydebug
Discord Discord
Python PyPI
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a malicious PyPi package named 'discordpydebug' that contains RAT malware targeting Discord developers.
2
What security implications are discussed in the article?
The article highlights the risk of downloading malicious packages from PyPI, which can compromise developers’ systems and expose sensitive data.
3
What time frame does the article specify for when the malware has been active?
The malware has been active since 2022.
4
Who are the primary targets of the malicious package?
The primary targets of the malicious package are developers working with Discord.
5
What products or software are affected by this malware?
The affected software includes the Python package 'discordpydebug' and the Discord application.