Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

spaysdatarbxPyPI

Malicious code in spaysdatarbx (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-5329
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall spaysdatarbx

What this malware does

spaysdatarbx is a Windows infostealer disguised as a Roblox DataStore library. On import spaysdata, init.py invokes main_entry() (wrapped in try/except: pass to stay silent), which performs three malicious actions: (1) reads %USERPROFILE%/AppData/Local/Roblox/LocalStorage/robloxcookies.dat, DPAPI-decrypts it, and POSTs the plaintext Roblox session cookie to a hardcoded Discord webhook (https://discord.com/api/webhooks/1499336276762038292/...); (2) walks Discord, Chrome, Edge, Brave, Opera, Yandex, and Firefox profile directories, force-kills Discord with taskkill /f /im Discord.exe to release leveldb locks, AES-GCM-decrypts auth tokens with each browser's DPAPI master key, and POSTs every recovered token to the same webhook; (3) establishes persistence by copying itself to %APPDATA%\MySystemUtility\ and writing an HKCU...\Run\MyPythonAutostartApp registry value that re-launches the stealer at every login, hiding the console window via ShowWindow(GetConsoleWindow(), 0). The package's advertised purpose ('Библиотека для работы с DataStore в Roblox') is a decoy — no DataStore functionality exists in main.py, only the stealer. Any developer who installs and imports this package has their Roblox session and all browser-stored Discord tokens sent to the attacker, plus a persistent autostart entry for ongoing theft.

The package exfiltrates Roblox cookies from the victim machine.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-spaysrbdata

Reasons (based on the campaign):

  • infostealer

Malicious versions

2 flagged
0.1.30.1.5

Indicators of compromise (SHA-256)

31b0b97326861aabb747f26e130a5dbda5ac78100fafbb3a3327b1981119e3a6
ddffc9e3413a0002eb53a77c72679297563add6c776b89475e9e0bb83d516d49
1bcaa4bf6f81efed82d35081ec059dfcd2f55e50b84f28d8b0ad4d8afe63089f
28acb1db885e57d4a1f6f5bcdfb316141626b89be210c550654266524d23acc7
a00fa386bd2921286903f63dd50f713af260c3b12586ee801b2f17fb5e85031f

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for spaysdatarbx (2 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging spaysdatarbx across your stack and pipelines.

  2. If you installed it — respond

    spaysdatarbx is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If spaysdatarbx was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks spaysdatarbx before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. spaysdatarbx on PyPI has been identified as a malicious package (versions 0.1.3, 0.1.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-06-spaysrbdataIN-MAL-2026-005401IN-MAL-2026-005402

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks spaysdatarbx-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.