“fallguys contained malicious code that attempted to read local sensitive files and exfiltrate information through a Discord webhook.” reads the npm’s advisory.
Every project that integrated the malicious library, upon execution will get the malicious code executed.
Experts noticed that the malicious package was designed to steal only specific sensitive information from the infected developers’ systems.
This malicious code would attempt to access the content of the following five local files and then post the data inside a Discord channel:
The first four files are LevelDB databases used common browsers like Chrome, Opera, Yandex Browser, and Brave. The files contain a user’s browsing history data.
The /AppData/Roaming/discord/Local\x20Storage/leveldb file is a sort of LevelDB database for the Discord Windows client that is used to store information on the channels a user has joined.
Experts speculate the malicious package was used to gather information on developers using it, such as the sites they were accessing.
“Remove the package from your system and ensure any compromised credentials are rotated.” concludes the advisory.
(SecurityAffairs – hacking, npm)