self-v8@8.3.9
Malicious code in self-v8 (npm)
Analysis
self-v8@8.3.9 contains a Discord token validator and exfiltrator. When imported, its check() function reads the running script file, extracts Discord tokens from a CONFIG object using regex, validates each token by logging into Discord via discord.js-selfbot-v13, and POSTs the validation results (including the full config snippet) to a Discord webhook at discord[.]com/api/webhooks/1450251813067423817/XJrDOIGOLOlIW2hsFTo0_BNjcX16FFSYEYHQRpqLZZm8Lx98BY4iGejC5r0FWZRLn2i5. The webhook receives all validated token identities and surrounding configuration, enabling the attacker to collect working Discord credentials silently.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 05:17 PM
- analyzed
- Jun 13, 2026, 05:18 PM
Related advisories
- node-fetch-lite@1.0.2
- vl-ui-body@10.1.1
- seed-to-private@1.0.1
- scoin_setting@1.0.18
- saps_secplayground_npm_ai@1.0.4
- rimo-env-validator@1.0.1
- houzidawang807@1.1.6
- renovate-config-doctolib@9.9.16
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.