MALICIOUS (1) campaign cataloged at 2026-08-03(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-08-instalogin1234¶
The package promises to be an Instagram CLI and offers "login". Entered credentials are sent to a Discord channel, and the user is presented with the Instagram website just opened in the browser.
Abuse categories¶
exfiltration_credentials
The package attempts to steal credentials, like passwords or API keys.
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
hxxps://discord.com/api/v9/channels/1246456414843437101/messages