discord-mfa@3.0.0
Malicious code in discord-mfa (npm)
Analysis
On Windows systems, the package drops a second-stage payload and installs persistence. It creates the directory %APPDATA%\Microsoft\Windows\WinSxS\Backup, downloads a script from hxxps://limbomail[.]com/attachment/yl8ulfsxnzrV[.]p9VNqox-hxFRxKJEnv20ByL1bUqiVp3- to winsvc.js, and executes it with node.exe as a detached process. It registers persistence via the registry Run key WinSvcHost, the HKCU\Environment UserInitMprLogonScript value, a Startup-folder VBScript (wsvc.vbs), and a scheduled task (schtasks /sc onlogon), and hides the dropped files with attrib +h +s. The package also functions as a Discord account-takeover tool that takes a victim's Discord token and password to mint an MFA token for vanity-URL sniping. C2/download host: limbomail[.]com.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 05:18 PM
- analyzed
- Aug 27, 2026, 05:19 PM
Related advisories
- core-js-buffer@1.0.0
- dolyame-boxy-atom-bnpl-navigation-arrow@35.6.5
- devplatform-spa-plugin-s3-module-loader@35.8.2
- bigops-create-manifest@35.2.4
- bigops-cobrowsing@35.4.9
- terminal-kit-tslint-config@20.1.9
- twork-data-services-aggregator-sme-task-info@20.3.1
- statist-browser-typed-client-risktech.uwfrontantifraud.events@20.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.