discord-resolvers@3.4.2
Malicious code in discord-resolvers (npm)
Analysis
Package named "discord-resolvers" (unrelated to its advertised "server backup" purpose) silently exfiltrates the host filesystem to an attacker-controlled Telegram channel. On execution it recursively walks the source directory — /root on Linux, the drive root on Windows, falling back to the current working directory — zips every file (excluding only node_modules/.npm/.git/.cache/proc/sys/dev/run/tmp), and uploads the archive to a hardcoded Telegram bot (a live bot token and chat id shipped in config.json) using the telegraf library. The archive is deleted locally after upload. The Telegram destination is hardcoded in the shipped config.json and controlled by the publisher, so any credentials, keys, or sensitive files present under the walked directory are sent to the attacker.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 01:50 AM
- analyzed
- Sep 15, 2026, 01:51 AM
Related advisories
- discord-players@3.4.2
- tracker-cloudflare@1.0.0
- real-router-telemetry@1.0.1
- test-in-one@1.0.0
- hydration-ui-dlx@1.0.0
- octopus-action@1.0.1
- spotify-url-infos@3.4.2
- remove-bg-serverless-azure@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.