The NPM repository has identified 17 malicious packages that were distributed using typosquatting, i.e., by assigning names similar to popular library names in hopes that users would make a typo when typing the name or fail to notice the differences when selecting a module from the list.
The packages discord-selfbot-v14, discord-lofy, discordsystem, and discord-vilao used a modified version of the legitimate library discord.js, which provides functions for interacting with the Discord API. The malicious components were integrated into one of the package files and included about 4,000 lines of code, convoluted by variable name obfuscation, string encryption, and code formatting violations. The code scanned the local filesystem for Discord tokens and, if found, sent them to server attacker's server.
The fix-error package was claimed to fix errors in the Discord selfbot but included a Trojan application called PirateStealer, which stole credit card numbers and Discord-related account information. The malicious component was activated by injecting JavaScript code into the Discord client.
The prerequests-xcode package included a Trojan for establishing remote access to the user's system, based on a Python application called DiscordRAT.
It is believed that access to Discord servers may have been required by the attackers to deploy botnet command points, act as a proxy for exfiltrating information from hacked systems, cover their tracks during attacks, distribute malware among Discord users, or resell premium accounts.
The packages wafer-bind, wafer-autocomplete, wafer-beacon, wafer-caas, wafer-toggle, wafer-geolocation, wafer-image, wafer-form, wafer-lightbox, octavius-public, and mrg-message-broker included code to send the contents of environment variables, which could, for example, include access keys, tokens, or passwords to continuous integration systems or cloud environments such as AWS.
Source: opennet.ru
