
Cloud Vulnerability DB
A community-led vulnerabilities database
The npm package 'discord-fix' was identified as a malicious package and subsequently removed from the npm package registry. This security incident was discovered and disclosed on January 29, 2021, with the latest update to the advisory on January 9, 2023. The vulnerability affects all versions of the discord-fix package (>= 0.0.0), and no patched versions are available (GitHub Advisory).
The vulnerability has been classified with Critical severity and is associated with CWE-506. No CVE identifier has been assigned to this security issue, but it is tracked under the GitHub Security Advisory ID GHSA-qv2g-99x4-45x6 (GitHub Advisory).
Any computer that has installed or executed this package should be considered fully compromised. The malicious package potentially grants full control of the affected system to unauthorized external entities (GitHub Advisory).
The package was confirmed as malicious and was removed from the npm package registry. Due to its nature as a malicious package, any installation or execution of the package should be considered an active exploitation (GitHub Advisory).
All secrets and keys stored on affected computers should be immediately rotated from a different, uncompromised system. While the package should be removed from affected systems, it's important to note that removal may not eliminate all malicious software resulting from its installation, as the system may have been completely compromised (GitHub Advisory).
The security community, including Sonatype, actively reported and analyzed this malicious package as part of ongoing efforts to identify and remove malicious Discord-related malware in the npm ecosystem (Sonatype Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."