Logo
pypi

discordnv@0.8.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-11050

Ecosystem

pypi

Summary

On import discordnv, __init__.py invokes main_entry() which hides the console window, walks Discord/Chrome/Edge/Brave/Opera/Yandex/Firefox LevelDB/SQLite stores to extract Discord authentication tokens, reads and DPAPI-decrypts Roblox robloxcookies.dat, and POSTs the harvested credentials to a hardcoded Discord webhook at discord.com/api/webhooks/1528403989983662194/... and a Google Apps Script endpoint at script.google.com/macros/s/AKfycbwa.../exec. add_to_startup() writes an HKCU\Software\Microsoft\Windows\CurrentVersion\Run entry named discordnv pointing at the invoking Python/exe so the stealer re-runs on every user logon. All operations are wrapped in bare try/except to swallow errors and avoid alerting the user. The package's advertised purpose (a Roblox DataStore helper) is unrelated to the observed behavior.

Source: amazon-inspector (2f79139609558d677545faa7d5f1d30ec31a54abe9fba990117ec0d27ea3ba48)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.