QID 983952
QID 983952: Nodejs (npm) Security Update for discordi.js (GHSA-fv9m-f7w4-889c)
The `discordi.js` package is malware that attempts to discover and exfiltrate a user's [Discord](https://discordapp.com/) credentials, sending them to pastebin. All versions have been unpublished from the npm registry. ## Recommendation Do not install / use this module. It has been unpublished from the npm registry but may exist in some caches. Any users that logged into Discord using this library will need to change their credentials.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fv9m-f7w4-889c for updates pertaining to this vulnerability.
Vendor References
- GHSA-fv9m-f7w4-889c -
github.com/advisories/GHSA-fv9m-f7w4-889c
CVEs related to QID 983952
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fv9m-f7w4-889c | discordi.js |
|