NPM Developers about the removal of the package from the repository due to the detection of malicious activity. In addition an ASCII art splash screen featuring the character from the game 'Fall Guys: Ultimate Knockout', the specified module included code attempting to transmit certain system files via a webhook to the Discord messenger. The module was published in early August but only managed to reach 288 downloads before being blocked.
The malicious activity targeted the compromise of Windows users. The following files were transmitted externally, including a database with browsing history from Chromium-based browsers and the Discord client (it is assumed that the module was blocked at the stage of collecting user data, and a more dangerous malware could have been delivered in one of the updates):
- /AppData/Local/Google/Chrome/User\x20Data/Default/Local\x20Storage/leveldb
- /AppData/Roaming/Opera\x20Software/Opera\x20Stable/Local\x20Storage/leveldb
- /AppData/Local/Yandex/YandexBrowser/User\x20Data/Default/Local\x20Storage/leveldb
- /AppData/Local/BraveSoftware/Brave-Browser/User\x20Data/Default/Local\x20Storage/leveldb
- /AppData/Roaming/discord/Local\x20Storage/leveldb
Source: opennet.ru
