Executive brief
The fast-requests npm package contains obfuscated malware that steals Discord user authentication tokens and uploads them to a remote server. Attackers can exploit compromised Discord accounts to make unauthorized purchases if credit cards are linked to those accounts, resulting in direct financial fraud and account takeover.
Technical details
The fast-requests npm package contains obfuscated malware (CWE-506) that is executed upon installation or usage. The malware exfiltrates Discord user authentication tokens by collecting them from the local system or process memory and transmitting them to a remote attacker-controlled server. No authentication or user interaction is required for the attack; merely installing and using the package triggers the malicious behavior. An attacker who obtains Discord tokens can access user accounts and perform actions including unauthorized purchases through linked payment methods. All versions of the package are affected and the package should be immediately removed from all environments.
Affected products
- npm fast-requests all versions
Timeline
- 2020-09-03: disclosed: Advisory published on GitHub Security Advisory Database