This module implements clear and straightforward data exfiltration: it enumerates local files, filters recent small images, reads them, and uploads them to a hardcoded external Discord webhook. This is malicious in essentially all benign contexts (unauthorized file leakage). Treat this code as a high-risk indicator of compromise or backdoor; do not trust or ship it. Immediate remediation: remove the code, rotate any credentials or webhooks if present elsewhere, and inspect systems for prior exfiltration events (network logs, webhook receipts).
Live on pypi for 121 days, 13 hours and 14 minutes before removal. Socket users were protected even while the package was live.