LWA-2026-12141 MAL-2026-16214 ↗ confirmed malware

discord-resolvers@3.4.2

Malicious code in discord-resolvers (npm)

T1005 · Data from Local SystemT1567 · Exfiltration Over Web ServiceT1041 · Exfiltration Over C2 ChannelT1059 · Command and Scripting Interpreter

Analysis

Package named "discord-resolvers" (unrelated to its advertised "server backup" purpose) silently exfiltrates the host filesystem to an attacker-controlled Telegram channel. On execution it recursively walks the source directory — /root on Linux, the drive root on Windows, falling back to the current working directory — zips every file (excluding only node_modules/.npm/.git/.cache/proc/sys/dev/run/tmp), and uploads the archive to a hardcoded Telegram bot (a live bot token and chat id shipped in config.json) using the telegraf library. The archive is deleted locally after upload. The Telegram destination is hardcoded in the shipped config.json and controlled by the publisher, so any credentials, keys, or sensitive files present under the walked directory are sent to the attacker.

analyzed by
Leitwacht
first seen
Sep 15, 2026, 01:50 AM
analyzed
Sep 15, 2026, 01:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.