LWA-2026-12103 MAL-2026-16213 ↗ confirmed malware

discord-players@3.4.2

Malicious code in discord-players (npm)

T1005 · Data from Local SystemT1567 · Exfiltration Over Web ServiceT1059.007 · JavaScript

Analysis

discord-players@3.4.2 is a Telegram-based data exfiltration tool disguised as a Discord package. On require, it zips the entire current working directory (including .env, source, and config files) and uploads the archive to a hardcoded Telegram chat via a hardcoded bot token. The bundled note.txt instructs the attacker to require() the package from their code, at which point it silently copies all host files and sends them to Telegram. The zip is created from process.cwd() with dot:true (includes hidden files) and sent through the Telegram Bot API to a hardcoded chat ID.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 05:27 AM
analyzed
Sep 14, 2026, 05:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.