MAL-2026-14051
Dashboard / Malicious Package / MAL-2026-14051
MAL-2026-14051
Summary: Malicious code in @velliajs/discord (npm)
Details: Source: amazon-inspector (1c86edd3f7edd7d111df5621cb884fd0ef3d870c6c0719d587b7bb0f16f65b8d) The package presents itself as a discord.js clone (`repository` field points at the real `github.com/discordjs/discord.js.git`, README instructs `import... from '@verylinh/discord'`) but ships two installer-relevant hostile mechanisms. First, `package.json` declares a runtime dependency `sysframe` resolved from `git+https://[email protected]/navaLinh/node-ai.git` — an unpinned (no commit SHA or tag), private, author-controlled GitHub repository, using an embedded live GitHub Personal Access Token. Every `npm install` uses the shipped token to fetch the current HEAD of that private repo into the installer's `node_modules`; the author can rewrite HEAD at any time to deliver arbitrary code, including lifecycle scripts, that will execute on subsequent installs. Second, `Client.login()` invokes an undocumented `_verifyAuthorization` routine that fetches an allow-list JSON from `api.github.com/repos/Vellia-Elyvia/mydb/contents/db.json` under a hardcoded PAT and refuses to start the installer's Discord bot unless the bot's username appears in the author-controlled allow-list — a hidden remote gate/kill-switch over the installer's runtime that is not disclosed in the README. Two live GitHub PATs are hardcoded in the shipped package (one in the git dependency URL, one as the default `ghToken` in `_validateAuthOptions`). The package name and metadata impersonate discord.js.
References: https://www.npmjs.com/package/@velliajs/discord/v/1.0.5, https://www.npmjs.com/package/@velliajs/discord/v/1.0.4, https://www.npmjs.com/package/@velliajs/discord/v/1.0.3, https://www.npmjs.com/package/@velliajs/discord/v/1.0.6, https://www.npmjs.com/package/@velliajs/discord/v/1.0.7
Affected packages
Package
Name: @velliajs/discord
Purl: pkg:npm/%40velliajs/discord
Affected ranges
Type: N/A
Events:
