Malicious npm Packages Posing as Solara Executor Target Discord, Browsers, and Crypto Wallets
ID: 03ab383c-3794-5fe1-813f-ce26734b5bfe
STIX ID: report--03ab383c-3794-5fe1-813f-ce26734b5bfe
Feed Name: cybersecurityNews.com
JFrog researchers uncovered a supply-chain campaign in which two malicious npm packages delivered a Windows dropper (solara 1.0.0/1.0.1.exe) that extracted an embedded Node.js runtime and scripts to steal Discord session tokens, browser credentials (via DPAPI and SQLite extraction), cookies, payment card data, and cryptocurrency wallet files; stolen data was compressed and exfiltrated to Gofile or attacker-controlled servers with summaries posted to a Discord webhook. The campaign also modifies Discord/BetterDiscord clients via injected scripts to persist and capture credentials, and while the npm packages and Dropbox payloads were removed, the secondary GitHub injection repository remained live at discovery; remediation recommended includes uninstalling the packages, reinstalling Discord, rotating credentials and auditing wallets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
