BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious Packages Use Discord Webhooks for Data Theft, Alert Experts

Malicious npm, Python, and Ruby Packages Use Discord Webhooks for Data Theft in North Korean Cyberespionage Campaign Targeting Web3 Developers

  • Cybersecurity researchers found malicious packages in npm, Python, and Ruby that use Discord webhooks to send stolen data.
  • Discord webhooks allow messages to be posted without authentication, making them a discreet tool for attackers to exfiltrate data.
  • Several packages steal sensitive files and system information, sending it to attacker-controlled Discord channels.
  • A North Korean campaign called Contagious Interview published 338 malicious npm packages targeting Web3 and cryptocurrency developers.
  • The campaign uses fake personas and typosquatting to trick users into running Malware that steals credentials and delivers backdoors.

Cybersecurity researchers have discovered multiple malicious software packages across the npm, Python, and Ruby ecosystems that use Discord as a command-and-control (C2) channel to transmit stolen data. These packages send sensitive information through Discord webhooks, which attackers control to receive data without needing authentication.

- Advertisement -

Discord webhooks are tools that post messages to channels without requiring a bot user or login, enabling attackers to quietly exfiltrate data. Socket researcher Olivia Brown explained, “webhook URLs are effectively write-only… defenders cannot read back prior posts just by knowing the URL.” This allows attackers to send stolen data discreetly without leaving a visible trace.

Among the identified packages are npm’s mysql-dumpdiscord, which steals developer configuration files; Python packages malinssx, malicus, and maliinn that contact Discord channels when installed; and Ruby’s sqlcommenter_rails, which collects host details and sensitive files before sending them to a Discord webhook. Brown noted the importance of this tactic, saying it lets threat actors avoid Hosting their own infrastructure and bypass firewall rules.

In addition, Socket revealed a North Korean threat group linked to a campaign called Contagious Interview published 338 malicious npm packages. These packages were downloaded over 50,000 times and deliver malware such as HexEval, XORIndex, and BeaverTail. The group created more than 180 fake identities and operated multiple C2 endpoints, targeting Web3, cryptocurrency, and blockchain developers.

The campaign tricks victims by offering fake job opportunities on platforms like LinkedIn, instructing targets to complete coding tests involving repositories referencing malicious npm packages. When executed, the malware steals browser credentials, cryptocurrency wallets, keystrokes, and screenshots. It also downloads additional backdoors like InvisibleFerret.

- Advertisement -

Many packages in this campaign use typosquatting, registering names similar to legitimate libraries, especially those related to Node.js and React. Security researcher Kirill Boychenko said, “Contagious Interview is not a cybercrime hobby… It is a state-directed, quota-driven operation with durable resourcing.” The campaign treats npm as a renewable source for initial access and removal of malicious packages alone is insufficient if the attacker accounts remain active.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

IBIT Draws April Inflows Despite Negative Returns

BlackRock's iShares Bitcoin ETF (IBIT) attracted inflows in April despite posting negative year-to-date returns,...

Strategy’s $1B Bitcoin Gamble Yields Just 1% Annual Return

Michael Saylor’s Strategy has returned to an unrealized $3.7 billion gain on its Bitcoin...

ZIGChain Summit 2026 Charts Onchain Finance Execution

The second annual ZIGChain Summit in Dubai highlighted the shift from exploration to execution...

Silver Fox Cyberattacks Target India, Russia With ABCDoor

The China-based Silver Fox group is targeting organizations in Russia and India with a...

MSFT May 2026 Outlook: Stagnation at $413 Predicted

Microsoft stock (NASDAQ: MSFT) opened Monday at $414 after surging more than 11% in...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading