Calling initMFA sends supplied Discord credentials and retrieves MFA tokens. TLS certificate verification is disabled, so a network attacker could intercept those credentials.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgIts TLS client disables certificate validation while connecting to Discord hosts.
lib/http.jsView on unpkg · L78The package advertises MFA bypass and automatic token refresh.
package.jsonView on unpkg · L2Its TLS client disables certificate validation while connecting to Discord hosts.
index.jsView on unpkg · L24The MFA flow sends the supplied account password to a Discord API endpoint.
index.jsView on unpkg · L156The MFA flow sends the supplied account password to a Discord API endpoint.
index.jsView on unpkg · L167This report applies to discord-mfa-solver@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgIts TLS client disables certificate validation while connecting to Discord hosts.
lib/http.jsView on unpkg · L78The package advertises MFA bypass and automatic token refresh.
package.jsonView on unpkg · L2Its TLS client disables certificate validation while connecting to Discord hosts.
index.jsView on unpkg · L24The MFA flow sends the supplied account password to a Discord API endpoint.
index.jsView on unpkg · L156The MFA flow sends the supplied account password to a Discord API endpoint.
index.jsView on unpkg · L167