http://mat.i2p/uncovering-the-discord-twitch-bots
No matter what we tried, we couldn’t decompile it into normal readable Python, so we just analyzed the bytecode using the dis Python module. There was a bunch of references to tokens and browser LocalStorage, where the token is stored. The malware also sent an http request to api. ipify. org (to grab the victim’s IP address), the user’s email and phone number, as well as the user’s nitro status.