LWA-2026-5095 confirmed malware

self-v8@8.3.9

Malicious code in self-v8 (npm)

T1552.001 · Credentials In FilesT1119 · Automated CollectionT1041 · Exfiltration Over C2 Channel

Analysis

self-v8@8.3.9 contains a Discord token validator and exfiltrator. When imported, its check() function reads the running script file, extracts Discord tokens from a CONFIG object using regex, validates each token by logging into Discord via discord.js-selfbot-v13, and POSTs the validation results (including the full config snippet) to a Discord webhook at discord[.]com/api/webhooks/1450251813067423817/XJrDOIGOLOlIW2hsFTo0_BNjcX16FFSYEYHQRpqLZZm8Lx98BY4iGejC5r0FWZRLn2i5. The webhook receives all validated token identities and surrounding configuration, enabling the attacker to collect working Discord credentials silently.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 05:17 PM
analyzed
Jun 13, 2026, 05:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.