Junglewise Threat Intelligence

carloprojectlesang malware in npm package

Severity: low · CVSS 3.1 · Published 2020-09-02

Vendors: npm.

Executive brief

The npm package carloprojectlesang contains obfuscated malware that steals Discord authentication tokens from users who install it. Once stolen, attackers can use these tokens to access Discord accounts and make purchases on behalf of users if credit cards are linked to those accounts, resulting in unauthorized charges and account compromise.

Technical details

This is a malicious package (CWE-506: Embedded Malicious Code) distributed via npm. All versions of carloprojectlesang contain obfuscated code that harvests Discord user tokens and exfiltrates them to a remote server controlled by the attacker. The attack requires only that a developer install and run the package in their environment—no special authentication or network preconditions are needed beyond basic npm installation. The malware captures session tokens that can be reused to hijack Discord accounts. Remediation requires immediate removal of the package and rotation of Discord tokens; users should also contact credit card companies if cards were linked to compromised accounts.

Affected products

  • npm carloprojectlesang all versions

Timeline

  • 2020-09-02: disclosed

References