Junglewise Threat Intelligence

whiteproject npm package malware distributing Discord tokens

Severity: low · CVSS 3.1 · Published 2020-09-02

Vendors: npm.

Executive brief

whiteproject is an npm package that contains obfuscated malware. Once installed, the malware secretly exfiltrates Discord user authentication tokens to remote servers, allowing attackers to access compromised Discord accounts and make fraudulent purchases if payment methods are linked to those accounts.

Technical details

This is a supply-chain attack vector involving malicious code injection into a publicly distributed npm package. The vulnerability leverages code obfuscation to hide malware that harvests Discord authentication tokens and transmits them to attacker-controlled infrastructure. The attack requires only installation of the compromised package (no authentication, local execution assumed during install or runtime). All versions of whiteproject are affected. Attackers who obtain stolen Discord tokens gain full account access, enabling fraud, account takeover, and unauthorized purchases on linked payment methods. The recommended remediation is immediate package removal and token revocation.

Affected products

  • npm whiteproject all versions

Timeline

  • 2020-09-02: disclosed

References