Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fv9m-f7w4-889c

Опубликовано: 06 авг. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

discordi.js is malware

The discordi.js package is malware that attempts to discover and exfiltrate a user's Discord credentials, sending them to pastebin.

All versions have been unpublished from the npm registry.

Recommendation

Do not install / use this module. It has been unpublished from the npm registry but may exist in some caches. Any users that logged into Discord using this library will need to change their credentials.

Пакеты

Наименование

discordi.js

npm
Затронутые версииВерсия исправления

<= 14.0.3

Отсутствует

EPSS

Процентиль: 42%
0.00199
Низкий

7.3 High

CVSS3

Дефекты

CWE-506

Связанные уязвимости

CVSS3: 7.3
nvd
больше 7 лет назад

discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.

EPSS

Процентиль: 42%
0.00199
Низкий

7.3 High

CVSS3

Дефекты

CWE-506