🔴 HIGHthreat

Discord Webhooks C2 - npm/PyPI/RubyGems Supply-Chain Exfil

Socket researchers document malicious packages across npm, PyPI, and RubyGems abusing Discord webhooks for stealthy C2 and exfiltration of secrets and host telemetry.

Vendors

DiscordnpmPyPIRubyGems

Threats

Supply chainC2Exfiltration

Targets

DevelopersCI/CD