Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Sophisticated ‘duer-js’ NPM Package Distributes ‘Bada Stealer’ Malware Targeting Windows and Discord Users

## Cybersecurity: NPM Package Malware Alert

Cybersecurity: NPM Package Malware Alert

A new malware threat has been identified in the NPM package registry, posing significant risks to developers and Windows users. The package, named duer-js , is masquerading as a legitimate tool but is designed to distribute malware.

The package was uploaded by a user identified as "luizaearlyx" and has been downloaded 528 times. Experts have raised concerns regarding its sophisticated attack methods, which could lead to severe consequences for users who have installed it.

Known as Bada Stealer , the malware employs a multi-stage attack strategy. Upon installation, it downloads an additional payload targeting Discord users . This secondary component integrates with the Discord application, enabling it to capture sensitive information during application startup.

The malware can collect various forms of sensitive data, including payment methods and authentication tokens, and bypasses two-factor authentication mechanisms.

The malware executes an information theft process by terminating running processes of browsers and Telegram to access locked files. It systematically searches for valuable data across multiple applications, including Discord, where it extracts authentication credentials and other sensitive information.

A new malware threat has been identified in the NPM package registry, posing significant risks to developers and Windows users.
Daniel Brooks · Thehackingpost

Furthermore, the malware targets browser data, extracting decrypted passwords using the Windows Data Protection API (DPAPI), and collects cookies and autofill data such as credit card details. Cryptocurrency wallet users are also at risk, as the malware seeks out Exodus wallet files and browser-extension wallets.

Stolen data is exfiltrated via a Discord webhook and an alternative method using Gofile cloud storage. This redundancy ensures data transmission even if one channel fails. The malware creates text files containing sensitive information, which are then uploaded.

Immediate action is recommended for users who have installed the duer-js package:

Advertisement

Completely close and uninstall Discord via Windows settings. Delete all Discord-related folders within the %LOCALAPPDATA% directory. Reinstall Discord from the official website only. Remove node.exe files from the Windows Startup folder. Change all stored passwords in browsers and revoke Discord tokens. Enable two-factor authentication and review payment methods for unauthorized changes. Check cryptocurrency wallets and Steam accounts for suspicious activity.

These steps are crucial to remove the infection and protect against further compromises.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories