Executive brief
carloprojectdiscord is an npm package used by Discord application developers. All versions contain obfuscated malware that steals user Discord authentication tokens and sends them to a remote server, allowing attackers to hijack accounts and make unauthorized purchases if payment methods are linked.
Technical details
This is a malicious package vulnerability (CWE-506: Embedded Malicious Code). All versions of carloprojectdiscord contain obfuscated malware that harvests Discord user tokens and exfiltrates them to an attacker-controlled remote server. The attack vector is network-based and requires no authentication or user interaction beyond installing the package. An attacker who obtains a stolen token can impersonate the victim on Discord, access account data, and perform unauthorized actions including making purchases on accounts with linked credit cards. The only mitigation is complete removal of the package.
Affected products
- npm carloprojectdiscord all versions
Timeline
- 2020-09-02: disclosed