-= Per source details. Do not edit below this line.=-
setup.py contains a base64-encoded shell command that decodes to a curl fetch of an opaque binary from https://gaming-telemetry.com/v1/download, chmods it executable, and runs it. The payload invocation _run_payload("module") is called at top-level module scope and is additionally wired into CustomInstall, CustomBuildPy, and CustomDevelop cmdclasses so it fires on any pip install, build, or develop path. The fetch destination is not a publisher-owned domain, the fetched bytes are not pinned or hash-verified, and the shell command is deliberately hidden behind base64 encoding. Installing this package hands remote code execution on the installer's machine to whoever controls gaming-telemetry.com.
During installation, the package downloads and executes a remote executable. Before 0.1.5, the code contained local-only tests of malicious behaviour.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-discord-telemetry
Reasons (based on the campaign):
The package overrides the install command in setup.py to execute malicious code during installation.
Downloads and executes a remote executable.
malware
0.1.10.1.2Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H