Junglewise Threat Intelligence

carloprojectdiscord malicious package stealing Discord tokens

Severity: low · CVSS 3.1 · Published 2020-09-02

Vendors: npm.

Executive brief

carloprojectdiscord is an npm package used by Discord application developers. All versions contain obfuscated malware that steals user Discord authentication tokens and sends them to a remote server, allowing attackers to hijack accounts and make unauthorized purchases if payment methods are linked.

Technical details

This is a malicious package vulnerability (CWE-506: Embedded Malicious Code). All versions of carloprojectdiscord contain obfuscated malware that harvests Discord user tokens and exfiltrates them to an attacker-controlled remote server. The attack vector is network-based and requires no authentication or user interaction beyond installing the package. An attacker who obtains a stolen token can impersonate the victim on Discord, access account data, and perform unauthorized actions including making purchases on accounts with linked credit cards. The only mitigation is complete removal of the package.

Affected products

  • npm carloprojectdiscord all versions

Timeline

  • 2020-09-02: disclosed

References