Junglewise Threat Intelligence

discord.js-user malicious package with token theft

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

discord.js-user is an npm package designed to interact with the Discord messaging platform. All versions of this package contain malicious code that steals users' Discord authentication tokens and exfiltrates them to a remote server, compromising account security and enabling account takeover.

Technical details

This is a supply-chain attack involving malicious code injection (CWE-506) in an npm package. The package contains code that extracts the user's Discord token and transmits it to an attacker-controlled remote server. The attack requires the compromised package to be installed and executed in a user's environment. There is no patch available for this package; the recommended remediation is complete removal from all environments and immediate invalidation of any exposed Discord tokens to prevent unauthorized account access.

Affected products

  • npm discord.js-user all versions

Timeline

  • 2020-09-03: disclosed

References