Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Snyk finds PyPi malware that steals Discord and Roblox credential and payment info

Blog post from Snyk

Post Details
Company
Date Published
Author
Raul Onitza-Klugman
Word Count
1,689
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

Snyk security researchers have identified 12 unique pieces of malware, all belonging to the same actor, that were found in PyPi packages. These malicious packages steal Discord and Roblox credential and payment information by executing malicious executable files downloaded from the Discord content delivery network (CDN) onto Windows machines. The malware targets data stored for everyday user applications, including Google Chrome passwords, cookies, web history, search history, and bookmarks. It also injects a persistent malicious agent into the Discord app to relay alarming amounts of information to attackers. Additionally, it steals Roblox cookies and user data by executing executable files downloaded from the Roblox CDN onto Windows machines. The malware uses PyInstaller to bundle its application and dependencies into one package, attempting to avoid detection by bundling in dependencies instead of downloading them from a remote server. Snyk's security researchers continually monitor open source ecosystems for malicious packages using static analysis techniques to identify and flag suspicious packages.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 520 77 43 +69%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.