Threat Actors Exploit Discord Webhooks for C2 via npm, PyPI, and Ruby Packages

Threat Actors Exploit Discord Webhooks for C2 via npm, PyPI, and Ruby Packages

Threat actors are increasingly using Discord webhooks as covert command-and-control channels within open-source packages, allowing for the stealthy exfiltration of sensitive data. This tactic leverages hard-coded webhook URLs to bypass security measures and exfiltrate secrets from developer environments.
Oct 13, 2025 Actor: Unknown Sector: Software Development Region: Global