Cybercriminals have discovered a new way to exploit Discord webhooks as command and control (C2) channels in popular programming language ecosystems. Unlike traditional C2 servers, webhooks offer free, low-profile data extraction that seamlessly integrates with regular HTTPS traffic.
See also: New ChaosBot malware uses Discord channels

Over the past month, malicious packages on npm, PyPI , and RubyGems have been silently siphoning sensitive files and telemetry from developer machines and continuous integration environments. The first observations involved a seemingly innocent npm module named mysql-dumpdiscord. When installed or executed, it looks for configuration and environment files—such as config[.]json, [.]env , and ayarlar[.]js—reads their contents, and then performs an HTTP POST to a predefined Discord webhook URL.
The webhook, which is controlled by the attacker and embedded as a string constant, receives the contents of each file, with larger files truncated to 1,900 characters to fit Discord's message limits. Socket.dev only discovered this technique after network monitoring flagged an unusual increase in POST requests to discord[.]com/api/webhooks/….
Further investigation revealed a second proof of concept on npm that leverages the discord.js. This minimalist approach converts any string passed to the function into a C2 message, bypassing host-based detection that looks for unusual domains or signatures.
See also: You can now try Fortnite directly on Discord

Across ecosystems, threat actors employ similar tactics. In Python’s PyPI registry, a package named malinssx bypasses the setuptools. During pip install, it serializes a Vietnamese notification message—“Someone just installed the maladicus package via pip!”—and sends it to its Discord webhook. Any network errors are ignored, and the normal installation process continues without a hitch.
In RubyGems, a modified version of sqlcommenterrails collects host metadata—such as the contents of /etc/passwd, DNS servers, current user, and public IP—and formats it into a multi-line JSON payload. This is then POSTed to a webhook over HTTPS. Error handling is silent, ensuring that there is no interruption to the gem installation.
These packages exploit hooks during installation to achieve persistence and stealth. By bypassing installation commands (install[.]run in Python, gemspec hooks in Ruby), the malicious code is executed before the computer's security checks alert it to any behavior during execution. This early execution means that secrets are extracted long before code analysis or endpoint protection is triggered.
See also: Discord Invite: Hackers insert malicious links with AsyncRAT

Additionally, using Discord's infrastructure avoids raising suspicions from static whitelists that allow traffic to discord[.]com for business collaboration, turning a trusted domain into a secret data line.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
