Malicious NPM project steals browser info and Discord accounts

Read the original article: Malicious NPM project steals browser info and Discord accounts


Security researchers discovered today an npm package that contains malicious code designed to steal sensitive Discord and browser files. Sonatype researcher Ax Sharma discovered an npm package, dubbed discord.dll, that contains malicious code designed to steal sensitive files from a user’s browsers and Discord application. The malicious JavaScript library was uploaded to the npm packet repository […]

The post Malicious NPM project steals browser info and Discord accounts appeared first on Security Affairs.


Read the original article: Malicious NPM project steals browser info and Discord accounts