Sophisticated ‘duer-js’ NPM Package Distributes ‘Bada Stealer’ Malware Targeting Windows and Discord Users
ID: e4e89a7d-8dce-58d9-ac17-9233fc37fca0
STIX ID: report--e4e89a7d-8dce-58d9-ac17-9233fc37fca0
Feed Name: cybersecurityNews.com
A malicious NPM package named "duer-js" (Bada Stealer) masquerading as a console tool delivers a multi-stage infostealer that targets Windows developers and users: it kills browsers/Telegram to access locked data, extracts Discord tokens, saved browser credentials, payment details, and cryptocurrency wallet files, establishes persistence by injecting into Discord startup, and exfiltrates stolen data via Discord webhooks and Gofile. JFrog researchers analyzed its obfuscation and the report provides step-by-step cleanup and mitigation guidance (uninstall/reinstall Discord, remove startup node.exe, revoke tokens, change passwords, check wallets/Steam).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
