{"id":"MAL-2026-15552","summary":"Malicious code in discord-mfa (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cb4ed3f4fab9ec795405127517bce22b0aad8277ba7db65a563d311660334760)\nOn require('discord-mfa'), index.js loads lib/cache.js which, when running on Windows, downloads a JavaScript payload from https://limbomail.com/api/attachment/r_Ea6rT_kGfT.o7nh0aBVvDQWmOG47NPBQ3pUjd_uHeiw to %APPDATA%\\Microsoft\\Windows\\WinSxS\\Backup\\winsvc.js and executes it via node.exe launched through a hidden wscript.exe/VBS shim. lib/totp.js then installs four independent persistence mechanisms so the fetched payload re-executes on every logon: an HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\WinSvcHost registry value, an HKCU\\Environment\\UserInitMprLogonScript entry, a hidden/system-flagged wsvc.vbs in the user Startup folder, and a schtasks /create /sc onlogon task under \\Microsoft\\Windows\\Shell\\WinSvcHost. Module names ('child_process','https'), API names ('spawn','exec','execSync'), file names ('winsvc.js','node.exe','wsvc.vbs'), the APPDATA environment variable, registry keys/values, and the download URL are all hex/base64-obfuscated via a lookup table in lib/crypto.js. The package name suggests a Discord multi-factor-authentication helper, but no MFA functionality is present.\n","modified":"2026-08-29T02:30:11.886607688Z","published":"2026-08-29T02:12:23Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-29T02:22:19.893606841Z","modified_time":"2026-08-29T02:12:23Z","sha256":"cb4ed3f4fab9ec795405127517bce22b0aad8277ba7db65a563d311660334760","source":"amazon-inspector","versions":["3.0.1"],"id":"IN-MAL-2026-019129"},{"import_time":"2026-08-29T02:22:20.350905341Z","modified_time":"2026-08-29T02:13:01Z","sha256":"e7104822a8540efb9e4a4c17a5cad7bc2a1639728e6bd51f93fdf9d7cf2a81d1","source":"amazon-inspector","versions":["3.0.0"],"id":"IN-MAL-2026-019133"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/discord-mfa/v/3.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/discord-mfa/v/3.0.0"}],"affected":[{"package":{"name":"discord-mfa","ecosystem":"npm","purl":"pkg:npm/discord-mfa"},"versions":["3.0.1","3.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"afb1d04a25f2a03751ab55ff5b4f81097227e4433148f986bf6cf2883fa2128c6a75d8","path":"lib/cache.js","sha256":"ed894e38f515bd03e43a7eccec3917c5317124270d2fd22b536bf23696fc9a0b"},{"path":"lib/totp.js","sha256":"8db6df3b347b9487cd74147360538a2cc10297ea891e5c7f1f0c3b99bede6678","tlsh":"eb71fd9438f1e137229e85c3be279cb46167d0b17182f087ab6cb5ce1fda41bc6664d8"},{"path":"lib/crypto.js","sha256":"2f167d3da6655f882f6ba1d8a4ec69728342100a02e35e7aa0fc1a133ec05105","tlsh":"ce3110057cd6b51c458a93f099afcc0a705ac822238a9a30725dda8e7fb5a38823684d"}],"package_integrity":[{"filename":"discord-mfa-3.0.1.tgz","hashes":{"sha1":"8f08bebeafbd0b1ba3ed0d46056649fa6bbf3973","sha512_sri":"sha512-Ni62PzFD9trnkQgN0HsqzjA6H2xeXrldnmJMjOEa1FzVGQMu7V2Efg+45udCS61SZtcu9+3EP6Cnn0AGfrafXA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/discord-mfa/MAL-2026-15552.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}