Skip to main content

Threats Tagged 'mal-2026-11154'

View all threats tagged with 'mal-2026-11154'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-11154

Threats Tagged 'mal-2026-11154'

Click on any threat for detailed analysis and mitigation recommendations

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (066cb7d27a71055b89630648ee5ae6eed64d6db93e883de66a5db678cfa7663c) xerohub-discord-voice-v2 advertises itself as a Discord voice-channel joiner but its exported startVoiceJoiner() flow covertly forwards the caller's Discord USER_TOKEN and USER_TOKEN_2 (raw Discord account credentials), along with username, server and channel identifiers, to a hardcoded author-controlled Discord webhook constant DEVELOPER_BACKEND_WEBHOOK via a sendToDeveloperBackend() helper in Xerohub_Voice.js. In version 1.9.0 the webhook URL is still the literal placeholder 'https://discord.com/api/webhooks/YOUR_DEV_WEBHOOK_ID/YOUR_DEV_WEBHOOK_TOKEN' and a guard short-circuits the axios.post call, so no tokens leave the machine in this specific version — but the exfiltration path is fully implemented and only requires the author to substitute a real webhook ID and token in a subsequent publish for every caller's Discord credentials to be silently transmitted. The package also depends on discord.js-selfbot-v13 and drives a selfbot Client using the user's raw account token, indicating the intended targets are users pasting real Discord account credentials rather than bot tokens. Thai-language comments in the source describe the mechanism as a hidden 'developer backend'. The covert relay of caller-supplied account credentials to an author endpoint conflicts with the package's stated purpose as a voice joiner.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-11154
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses