LWA-2026-11757 confirmed malware

discord-mfa-solver@1.0.2

Malicious code in discord-mfa-solver (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

discord-mfa-solver@1.0.2 installs a dependency named node-net-pool from a non-registry GitHub tarball URL (github[.]com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz) and requires it at module load in lib/cache.js, so the dependency's code executes on import. The dependency is a known-malicious package. The package's own code automates Discord MFA ticket generation and vanity-URL PATCH requests against discord[.]com (raw TLS 1.3 sockets with certificate validation disabled, rotating across discord[.]com/canary/ptb hosts).

analyzed by
Leitwacht
first seen
Aug 29, 2026, 09:36 PM
analyzed
Aug 29, 2026, 09:38 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.