⚡THE CORTEX PROTOCOL
🏠Home
🚨Threats ▾
🧩Patches
📚Books
🎬Mission Logs
🏠Home🚨Threats🧩Patches📚Books🎬Mission Logs
Home›Threads›Threat Intelligence
🔴 HIGHthreatOct 13, 2025

Discord Webhooks C2 - npm/PyPI/RubyGems Supply-Chain Exfil

Category:Threat Alerts / Threat Intelligence
Socket researchers document malicious packages across npm, PyPI, and RubyGems abusing Discord webhooks for stealthy C2 and exfiltration of secrets and host telemetry.

Vendors

DiscordnpmPyPIRubyGems

Threats

Supply chainC2Exfiltration

Targets

DevelopersCI/CD

Tags

#supply chain#open source#Discord webhooks#exfiltration#C2
Intelligence Source: Threat Actors Exploit Discord Webhooks for C2 via npm, PyPI, and Ruby Packages - GBHackers | Oct 13, 2025
More stories in Threat Intelligence →

🔗Related Threats

🔴Nov 1, 2025

Conduent Breach: 10.5M Records, 85 Days Dwell Time, 8.5TB Claimed

Enterprise
🔴Nov 1, 2025

PhantomRaven npm: 200+ Packages Using Remote Dynamic Dependencies

Supply Chain
🔴Nov 1, 2025

APT28 Expands Financial Targeting with Custom Loader + Banking Trojans

APT
🔴Nov 1, 2025

Agent Session Smuggling: Malicious AI Agents Weaponizing A2A Trust

AI Security
🔴Nov 1, 2025

Sandworm's Ukraine Campaign: Custom Webshell + LotL Persistence

APT
View All Threats →
⚡ THE CORTEX PROTOCOL© 2025 All Rights Reserved
AboutNewsletterContactPrivacyTerms
𝕏▶️