Lightweight Discord MFA authentication library. Raw TLS/1.3, multi-host rotation, Cloudflare bypass, TOTP. Zero dependencies.
Importing the package on Windows downloads and runs an obscured remote payload. It then establishes multiple Windows persistence mechanisms and periodically updates the payload.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/cache.js#virtual:normalized:round1View on unpkg · L20Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/crypto.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/cache.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/cache.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/cache.js#virtual:normalized:round1View on unpkg · L20Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/crypto.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/cache.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/cache.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkg