discordi.js is malware
High severity
GitHub Reviewed
Published
Aug 6, 2018
to the GitHub Advisory Database
•
Updated Sep 9, 2023
Description
Published to the GitHub Advisory Database
Aug 6, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 9, 2023
The
discordi.js
package is malware that attempts to discover and exfiltrate a user's Discord credentials, sending them to pastebin.All versions have been unpublished from the npm registry.
Recommendation
Do not install / use this module. It has been unpublished from the npm registry but may exist in some caches. Any users that logged into Discord using this library will need to change their credentials.
References