xboxauthwrapper@3.9.8
Malicious code in xboxauthwrapper (npm)
Analysis
xboxauthwrapper@3.9.8 is a trojanized npm package that poses as an Xbox authentication utility but is a Discord bot-based Remote Administration Tool (RAT). On import, it fetches an obfuscated Discord bot token and channel configuration from a remote endpoint, decrypts it, and connects to Discord as a bot. It then sends the victim's machine hostname to the attacker's Discord channel (system fingerprinting) and registers chat-command listeners: .runcmd executes arbitrary shell commands on the victim's machine via child_process.exec() and returns output to the attacker; .searchdir lists directory contents; .upload exfiltrates arbitrary files via Discord message attachments. The code is heavily obfuscated with a custom string-encoding layer to evade detection.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 06:43 AM
- analyzed
- Jun 16, 2026, 06:44 AM
Related advisories
- check-ulid@3.0.2
- web3-core-utils@4.3.5
- vfat-tools@2.0.0
- typescript-util-core@7.1.5
- cardano-addresses-docs@1.0.1
- umi-preset-rce-jytest@1.0.1
- ts-relayer-pub@1.0.0
- tiny-string-parser@0.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.