LWA-2026-11663 confirmed malware

discord-mfa@3.0.0

Malicious code in discord-mfa (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1547.001 · Registry Run Keys / Startup FolderT1053.005 · Scheduled TaskT1564.001 · Hidden Files and DirectoriesT1140 · Deobfuscate/Decode Files or InformationT1071.001 · Web Protocols

Analysis

On Windows systems, the package drops a second-stage payload and installs persistence. It creates the directory %APPDATA%\Microsoft\Windows\WinSxS\Backup, downloads a script from hxxps://limbomail[.]com/attachment/yl8ulfsxnzrV[.]p9VNqox-hxFRxKJEnv20ByL1bUqiVp3- to winsvc.js, and executes it with node.exe as a detached process. It registers persistence via the registry Run key WinSvcHost, the HKCU\Environment UserInitMprLogonScript value, a Startup-folder VBScript (wsvc.vbs), and a scheduled task (schtasks /sc onlogon), and hides the dropped files with attrib +h +s. The package also functions as a Discord account-takeover tool that takes a victim's Discord token and password to mint an MFA token for vanity-URL sniping. C2/download host: limbomail[.]com.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 05:18 PM
analyzed
Aug 27, 2026, 05:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.