Junglewise Threat Intelligence

fast-requests malicious package with Discord token stealer

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The fast-requests npm package contains obfuscated malware that steals Discord user authentication tokens and uploads them to a remote server. Attackers can exploit compromised Discord accounts to make unauthorized purchases if credit cards are linked to those accounts, resulting in direct financial fraud and account takeover.

Technical details

The fast-requests npm package contains obfuscated malware (CWE-506) that is executed upon installation or usage. The malware exfiltrates Discord user authentication tokens by collecting them from the local system or process memory and transmitting them to a remote attacker-controlled server. No authentication or user interaction is required for the attack; merely installing and using the package triggers the malicious behavior. An attacker who obtains Discord tokens can access user accounts and perform actions including unauthorized purchases through linked payment methods. All versions of the package are affected and the package should be immediately removed from all environments.

Affected products

  • npm fast-requests all versions

Timeline

  • 2020-09-03: disclosed: Advisory published on GitHub Security Advisory Database

References