DevOps security firm JFrog has discovered malicious npm packages that appear to have been developed by malware authors to target rivals.
On February 22, JFrog cybersecurity researchers Andrey Polkovnychenko and Shachar Menashe said that 25 malicious Node Package Manager (npm) packages had recently been detected by the firm’s scanners, many of which are Discord token stealers.
If an attacker is able to steal tokens, they can be used to infiltrate a victim’s account and hijack Discord servers. They can also be valuable assets suitable for sale in underground, criminal markets.
“This masquerading is probably due to the fact that colors.js is still one of the most installed packages in npm,” JFrog says.
In addition, other packages were found including Python remote code injectors and environmental variable stealers.
While the reported packages were “quickly” removed by npm maintainers, one package, in particular, caught JFrog’s eye. Called “Lemaaa,” the npm package is a library “meant to