When a caller invokes initMFA and refreshes MFA, the package submits supplied Discord credentials and returns reusable MFA authorization headers. This is a dangerous account-automation capability, although the inspected code does not exfiltrate to a non-Discord destination.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgThe library sends supplied account credentials to Discord's MFA completion endpoint.
index.jsView on unpkg · L167It exposes MFA authorization headers intended for subsequent Discord requests.
index.jsView on unpkg · L230This report applies to discord-mfa-solver@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgThe library sends supplied account credentials to Discord's MFA completion endpoint.
index.jsView on unpkg · L167It exposes MFA authorization headers intended for subsequent Discord requests.
index.jsView on unpkg · L230