Executive brief
The discordi.js npm package is malware designed to steal Discord user credentials and send them to external services. Any developer or user who installed this package and used it to authenticate to Discord has had their login credentials compromised and should immediately reset their passwords.
Technical details
The discordi.js package contains embedded malicious code (CWE-506) that targets Discord authentication credentials. Upon execution, the malware discovers and exfiltrates user credentials to pastebin. The attack requires only that a user install and run the package—no additional privileges, authentication, or user interaction beyond installation are needed. The vulnerability affects all versions up to 14.0.3, and no patch is available; the package has been unpublished from npm but may persist in build caches and mirrors.
Affected products
- discordi.js discordi.js ≤ 14.0.3
Timeline
- 2018-08-06: disclosed
- 2018-08-06: advisory