Security researchers at Sonatype have discovered an npm package ( JavaScript) containing malicious codedesigned to steal sensitive files from a user's browsers and Discord app.

The malicious code, named discord.dll, is still available via npm, a web portal, command-line utility, and package manager for JavaScript developers.
Developers use npm to load and then update libraries in their JavaScript projects, whether they are websites, desktop applications , or server applications
According to Sonatype, once discord.dll is installed on a system , it executes malicious code that searches the developer's computer and, after locating specific applications, attempts to recover the internal LevelDB databases .
These applications can be browsers such as Google Chrome, Brave, Opera, and Yandex browser, but also the Discord instant messaging application, popular today among most online gamers.

The files retrieved by the malware are LevelDB databases, which the aforementioned applications use to store information such as browsing history and various access credentials.
Discord.dll reads the files and attempts to publish their contents to a Discord channel (as a Discord webhook).
After conducting research, Sonatype determined that the malicious code was an improved version of a malicious library that appeared in August. Called fallguys, this library also collected the same information, albeit in a less sophisticated way.
The discord.dll package is still available on the npm registry, but Sonatype said it has already notified the npm security team and the package will likely be removed in the coming days. Researchers also reported that discord.dll is not the only malicious package that its author has created. There are ten others on the npm site, three of which contained malicious code that downloads and executes three mysterious EXE files.
