VDB
GCVE-110-OSM-2026-11417
GCVE-110-OSM-2026-11417
Advisory PublishedCVSS 8.8/10
This package steal a user’s Discord login token and send it to an attacker, potentially allowing unauthorized access to the victim’s account.
It does not automatically find the token during installation; just after installation another script (get.py) invoke through README hard-coded link to obtain the token and call log(token). The package’s log(token) function accepts a Discord token and sends it in an HTTP request to the attacker’s hard-coded Discord webhook. Because a Discord token acts like a session credential, the attacker may use it to access the victim’s account.
This package is a Discord token stealer. Its main function, log(token), sends Discord tokens to a hardcoded webhook controlled by the attacker. The package does not run automatically during installation; the malicious function executes only when called. Therefore, it is an information-stealing component rather than a dropper.
IOCs: webhook: https://canary.discord.com/api/webhooks/837355902540709949/6xMyMJPxQ5STOsK0l6QXR9E7rC5x1Ag_M5gafA05M5_OurmRVcoVxgJUW2iIKsKvvyOm;
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | discord-command | all (affected) | — |
Browse GCVE Records
805 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.