npm PyPI and RubyGems Packages Found Sending Developer Data to Discord Channels

Posted on October 14, 2025 • 1 min read • 60 words
Share via

Cybersecurity researchers have identified several malicious packages across npm, Python, and Ruby ecosystems that leverage Discord as a command-and-control (C2) channel to transmit stolen data to actor-controlled webhooks. Webhooks on Discord are a way to post messages to channels in the platform without requiring a bot user or authentication, making them

npm PyPI and RubyGems Packages Found Sending Developer Data to Discord Channels

Read on Hackernews

Cybersecurity researchers have identified several malicious packages across npm, Python, and Ruby ecosystems that leverage Discord as a command-and-control (C2) channel to transmit stolen data to actor-controlled webhooks. Webhooks on Discord are a way to post messages to channels in the platform without requiring a bot user or authentication, making them an attractive mechanism for attackers to

Follow Us

Everything coding, technology, and digital Life