Researchers have discovered several malicious Python packages on PyPI, the Python package repository, which were designed to steal credit card information, Discord authentication tokens, and inject code. The packages were downloaded around 30,000 times before being removed. The malware used simple obfuscation techniques and was able to gather system information and upload it to a webhook. The incident highlights the risks of trusting packages from public repositories without proper vetting.