LofyLife steals Discord tokens

LofyLife steals Discord tokens

Researchers have discovered an attack campaign named Lofylife that uses malicious npm packages, targeting Discord users to steal Discord tokens and users’ card data. The Python malware is a modified…
JFrog NPM Trio Tool

JFrog NPM Trio Tool

A trio of tools released by JFrog, to prevent malicious packages from slipping into their applications will be helpful for java developers . The tool package consists of  npm-secure-install, package-checker,…

Discord Servers Hijacked By Malicious NPM Packages

Researchers discovered 17 malicious packages in the NPM (Node.js package manager) repository that were developed to hijack Discord servers. The libraries allow stealing access tokens and environment variables from systems running giving…