Sophisticated ‘duer-js’ NPM Package Distributes ‘Bada Stealer’ Malware Targeting Windows and Discord Users
## Cybersecurity: NPM Package Malware Alert
Cybersecurity: NPM Package Malware Alert
A new malware threat has been identified in the NPM package registry, posing significant risks to developers and Windows users. The package, named duer-js , is masquerading as a legitimate tool but is designed to distribute malware.
The package was uploaded by a user identified as "luizaearlyx" and has been downloaded 528 times. Experts have raised concerns regarding its sophisticated attack methods, which could lead to severe consequences for users who have installed it.
Known as Bada Stealer , the malware employs a multi-stage attack strategy. Upon installation, it downloads an additional payload targeting Discord users . This secondary component integrates with the Discord application, enabling it to capture sensitive information during application startup.
The malware can collect various forms of sensitive data, including payment methods and authentication tokens, and bypasses two-factor authentication mechanisms.
The malware executes an information theft process by terminating running processes of browsers and Telegram to access locked files. It systematically searches for valuable data across multiple applications, including Discord, where it extracts authentication credentials and other sensitive information.
A new malware threat has been identified in the NPM package registry, posing significant risks to developers and Windows users.
Furthermore, the malware targets browser data, extracting decrypted passwords using the Windows Data Protection API (DPAPI), and collects cookies and autofill data such as credit card details. Cryptocurrency wallet users are also at risk, as the malware seeks out Exodus wallet files and browser-extension wallets.
Stolen data is exfiltrated via a Discord webhook and an alternative method using Gofile cloud storage. This redundancy ensures data transmission even if one channel fails. The malware creates text files containing sensitive information, which are then uploaded.
Immediate action is recommended for users who have installed the duer-js package:
Completely close and uninstall Discord via Windows settings. Delete all Discord-related folders within the %LOCALAPPDATA% directory. Reinstall Discord from the official website only. Remove node.exe files from the Windows Startup folder. Change all stored passwords in browsers and revoke Discord tokens. Enable two-factor authentication and review payment methods for unauthorized changes. Check cryptocurrency wallets and Steam accounts for suspicious activity.
These steps are crucial to remove the infection and protect against further compromises.
Based on reporting by Cyber Security News.
