discord-players@3.4.2
Malicious code in discord-players (npm)
Analysis
discord-players@3.4.2 is a Telegram-based data exfiltration tool disguised as a Discord package. On require, it zips the entire current working directory (including .env, source, and config files) and uploads the archive to a hardcoded Telegram chat via a hardcoded bot token. The bundled note.txt instructs the attacker to require() the package from their code, at which point it silently copies all host files and sends them to Telegram. The zip is created from process.cwd() with dot:true (includes hidden files) and sent through the Telegram Bot API to a hardcoded chat ID.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 05:27 AM
- analyzed
- Sep 14, 2026, 05:28 AM
Related advisories
- tracker-cloudflare@1.0.0
- real-router-telemetry@1.0.1
- test-in-one@1.0.0
- hydration-ui-dlx@1.0.0
- octopus-action@1.0.1
- spotify-url-infos@3.4.2
- remove-bg-serverless-azure@1.0.1
- openai-pr-reviewer@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.