Get a Pentest and security assessment of your IT network.

Cyber Security

Malicious NPM project steals Discord accounts, browser info

A heavily obfuscated and malicious NPM project is used to steal Discord user tokens and browser information from unsuspecting users. NPM is a JavaScript package manager that allows developers to download and integrate different JS modules from a public registry containing over one million packages. The ‘discord.dll’ project has been available on NPM for five months and has been downloaded one hundred times. The module is believed to be based on another project called ‘JSTokenGrabber’ that was previously on GitHub. Sonatype also discovered three other suspicious packages from the same author named ‘Discord.app’ and ‘ac-addon’

Source: https://www.bleepingcomputer.com/news/security/malicious-npm-project-steals-discord-accounts-browser-info/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security