Malicious code in discord-token-generator (PyPI)
-= Per source details. Do not edit below this line.=-
During import, package executes the embedded executable. It is an infostealer named internally as "NBSteal", focused on exfiltrating data from browsers, Telegram, Discord, Roblox and other gaming platforms, and other credentials.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-discord-token-generator
Reasons (based on the campaign):
infostealer
files-exfiltration
obfuscation
exfiltration-browser-data
malware
target:telegram
exfiltration-credentials
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(PoC 존재) | ×1.20 |
| VPI | 66.00 |
VPI 공식 vpi-v1 기준