Data Security, Threat Intelligence

Malicious packages exfiltrate data via Discord C2

Laptop Screen Warning Alert: Cyber Attack, Virus, Malware, Spyware, System Hacked

Multiple nefarious npm, Python, and Ruby packages have been exfiltrating pilfered data to actor-controlled webhooks by exploiting Discord as a command-and-control channel, reports The Hacker News.

While the npm package 'mysql-dumpdiscord' drains developer configuration file content to a Discord webhook, the npm package 'nodejs[.]discord' harnesses the webhook for log alerts, according to findings from Socket's Threat Research Team.

On the other hand, a trio of PyPI packages leveraged Discord as a C2 through channel-directed HTTP requests, while the Ruby package 'sqlcommenter_rails' delivered pilfered host data to a hard-coded webhook.

"Abuse of Discord webhooks as C2 matters because it flips the economics of supply chain attacks. By being free and fast, threat actors avoid hosting and maintaining their own infrastructure. Also, they often blend in to regular code and firewall rules, allowing exfiltration even from secured victims," said Socket researcher Olivia Brown.

Such findings follow the discovery of over 300 illicit npm packages spread as part of the North Korean Contagious Interview campaign.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds