VDB

GCVE-110-OSM-2026-11417

GCVE-110-OSM-2026-11417
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 31, 2026
This package steal a user’s Discord login token and send it to an attacker, potentially allowing unauthorized access to the victim’s account. It does not automatically find the token during installation; just after installation another script (get.py) invoke through README hard-coded link to obtain the token and call log(token). The package’s log(token) function accepts a Discord token and sends it in an HTTP request to the attacker’s hard-coded Discord webhook. Because a Discord token acts like a session credential, the attacker may use it to access the victim’s account. This package is a Discord token stealer. Its main function, log(token), sends Discord tokens to a hardcoded webhook controlled by the attacker. The package does not run automatically during installation; the malicious function executes only when called. Therefore, it is an information-stealing component rather than a dropper. IOCs: webhook: https://canary.discord.com/api/webhooks/837355902540709949/6xMyMJPxQ5STOsK0l6QXR9E7rC5x1Ag_M5gafA05M5_OurmRVcoVxgJUW2iIKsKvvyOm;

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowndiscord-commandall (affected)

References

vendor

Browse GCVE Records

805 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›