Bitcoin Forum
May 24, 2024, 08:31:47 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: PSA. Discord users beware!!!!  (Read 203 times)
d57heinz (OP)
Legendary
*
Offline Offline

Activity: 1453
Merit: 1011


Bitcoin Talks Bullshit Walks


View Profile
October 28, 2019, 01:27:16 AM
 #1

if you missed in the past few days.  I know of lot of this forum moved to discord.  Be Careful

https://qr.ae/TWHxAd

https://www.bleepingcomputer.com/news/security/discord-turned-into-an-info-stealing-backdoor-by-new-malware/?utm_source=quora&utm_medium=referral


BR
Doug

As in nature, all is ebb and tide, all is wave motion, so it seems that in all branches of industry, alternating currents - electric wave motion - will have the sway. ~Nikola Tesla~
thefix
Legendary
*
Offline Offline

Activity: 1049
Merit: 1001



View Profile
October 28, 2019, 11:19:04 PM
 #2


Thanks for the info, it looks like its mainly associated with the app and not the web browser version. I will dig around more but so far it looks like people need to take some steps to uninstall the app and check locations mentioned in the article.
leowonderful
Legendary
*
Offline Offline

Activity: 1624
Merit: 1129


Bitcoin FTW!


View Profile
October 29, 2019, 01:35:01 AM
 #3

I actually initially thought this sort of malware was transferred through communicating through the actual Spidey Bot on Discord, but I'm glad that's not the case and I assume it spreads via normal vectors other viruses typically take with Windows. Still checked my Discord files either way and they seem to be fine, but if you don't have time to read the entire article, here's how you can know if you've been infected or not:

To check the %AppData%\Discord\[version]\modules\discord_modules\index.js simply open it in Notepad and it should only contain the single line of "module.exports = require('./discord_modules.node');" as shown below.

For the %AppData%\Discord\[version]\modules\discord_desktop_core\index.js file, it should only contain the "module.exports = require('./core.asar');" string as shown below.

[version] is the numbered file inside Discord, something like 0.0.305 or something of the sort.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!