LWA-2026-5547 confirmed malware

yellow-discord-lookup-v1@1.0.3

Malicious code in yellow-discord-lookup-v1 (npm)

T1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1071.001 · Web Protocols

Analysis

The package index.js is heavily obfuscated with a custom eval/decodeURI/XOR decoding scheme and anti-tamper protection that hides its actual behaviour. The publisher ([account]) previously published a malicious version of this same package name. At runtime the obfuscated code decodes and evaluates a hidden payload, which is consistent with C2 beaconing, data exfiltration, or Discord token harvesting — the package claims to be a Discord user/application/guild info lookup tool but its code is fully obfuscated to prevent inspection of what it actually does with the network calls it makes (via axios dependency). No install hook required — execution happens on require().

analyzed by
Leitwacht
first seen
Jun 16, 2026, 09:27 AM
analyzed
Jun 16, 2026, 09:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.