OSV ID
MAL-2026-5334
Ecosystem
pypi
Summary
On import spaysdata, the package's __init__.py invokes main_entry() in spaysdata/main.py, which performs three attacker-benefit actions automatically: (1) reads %USERPROFILE%/AppData/Local/Roblox/LocalStorage/robloxcookies.dat, decrypts it via win32crypt.CryptUnprotectData, and POSTs the cleartext Roblox session cookies to a hardcoded Discord webhook (discord.com/api/webhooks/1513603677913616544/...); (2) enumerates Discord, Discord Canary, Lightcord, Chrome, Edge, Brave, Yandex, Opera, and Firefox profile directories, decrypts dQw4w9WgXcQ-encrypted tokens using DPAPI + AES-GCM, kills Discord.exe via taskkill, and POSTs each token plus user info to the same webhook; (3) copies the running file to %APPDATA%/MySystemUtility/ and writes HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MyPythonAutostartApp to re-execute the stealer on each user login, with the console window hidden via ShowWindow(0). The package's advertised purpose (pyproject.toml description: "Library for working with DataStore in Roblox") is a cover story — no DataStore functionality exists in the source; only credential-theft and persistence code is shipped.
Source: amazon-inspector (d4bae51ef6cd61eb9bfc38ac2d8dd8ad1f38d22c4e55b8ccdfc53cd2ed94076f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.