logo

Sophisticated ‘duer-js’ NPM Package Distributes ‘Bada Stealer’ Malware Targeting Windows and Discord Users

ID: e4e89a7d-8dce-58d9-ac17-9233fc37fca0

STIX ID: report--e4e89a7d-8dce-58d9-ac17-9233fc37fca0

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malicious NPM package named "duer-js" (Bada Stealer) masquerading as a console tool delivers a multi-stage infostealer that targets Windows developers and users: it kills browsers/Telegram to access locked data, extracts Discord tokens, saved browser credentials, payment details, and cryptocurrency wallet files, establishes persistence by injecting into Discord startup, and exfiltrates stolen data via Discord webhooks and Gofile. JFrog researchers analyzed its obfuscation and the report provides step-by-step cleanup and mitigation guidance (uninstall/reinstall Discord, remove startup node.exe, revoke tokens, change passwords, check wallets/Steam).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.