logo

Malicious npm Packages Posing as Solara Executor Target Discord, Browsers, and Crypto Wallets

ID: 03ab383c-3794-5fe1-813f-ce26734b5bfe

STIX ID: report--03ab383c-3794-5fe1-813f-ce26734b5bfe

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-14

Date Updated: 2026-04-21

Author: Dhivya

...
...

JFrog researchers uncovered a supply-chain campaign in which two malicious npm packages delivered a Windows dropper (solara 1.0.0/1.0.1.exe) that extracted an embedded Node.js runtime and scripts to steal Discord session tokens, browser credentials (via DPAPI and SQLite extraction), cookies, payment card data, and cryptocurrency wallet files; stolen data was compressed and exfiltrated to Gofile or attacker-controlled servers with summaries posted to a Discord webhook. The campaign also modifies Discord/BetterDiscord clients via injected scripts to persist and capture credentials, and while the npm packages and Dropbox payloads were removed, the secondary GitHub injection repository remained live at discovery; remediation recommended includes uninstalling the packages, reinstalling Discord, rotating credentials and auditing wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.