Malicious npm package caught trying to steal sensitive Discord and browser files

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,154
The npm security team has removed a malicious JavaScript library from the npm portal that was designed to steal sensitive files from an infected users' browser and Discord application.

The malicious package was a JavaScript library named "fallguys" that claimed to provide an interface to the "Fall Guys: Ultimate Knockout" game API.

However, after developers downloaded the library and integrated it inside their projects, when the infected dev would run their code, the malicious package would also execute.

Per the npm security team, this code would attempt to access five local files, read their content, and then post the data inside a Discord channel (as a Discord webhook).
The npm security team advises that developers remove the malicious package from their projects.

The malicious package was available on the site for two weeks, during which time it was downloaded nearly 300 times.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top