Junglewise Threat Intelligence

npm discord-fix malicious package

Severity: info · Published 2021-01-29

Vendors: npm.

Executive brief

The discord-fix npm package was identified as malicious and removed from the npm registry. Any system with this package installed should be considered fully compromised, as the malicious code grants outside attackers complete control of the computer. Organizations must immediately revoke all secrets, API keys, and credentials from unaffected systems and perform a full security investigation.

Technical details

This is a supply-chain attack via a malicious npm package (CWE-506: Embedded Malicious Code). The discord-fix package contained intentionally malicious code designed to compromise systems upon installation. The attack requires only that a developer or automated system install the package from the npm registry—no authentication bypass or complex exploitation is needed. Upon execution, the malware grants full system control to remote attackers. The package has been removed from npm, but there is no reliable way to ensure complete removal of all implants from compromised systems without professional incident response.

Affected products

  • npm discord-fix 0.0.0 and later

Timeline

  • 2021-01-29: disclosed
  • other: Package removed from npm registry

References