Discord Desktop Core Injection
Malware modifies the Discord desktop client's discord_desktop_core/index.js to inject arbitrary JavaScript that runs with full access to the Discord process. This enables token theft, persistent surveillance of Discord activity, and secondary payload execution every time Discord launches.
Detection / Fingerprint
- File writes to
%APPDATA%/Discord*/discord_desktop_core/index.js - Creation of a
ThiefCator similarly named subdirectory underdiscord_desktop_core - Relaunch of
Discord.exeafterindex.jsmodification - Network requests to Discord API v9/v10 from processes not matching known Discord paths
Implementation Patterns Observed
In novashadow the malware:
- Fetches a JavaScript template from a remote URL (
DSCINJ_URL) - Patches placeholders (
%TRANSFER_URL%,%DISABLE_2FA%) - Writes the patched script to
discord_desktop_core/index.js - Creates a
ThiefCatmarker directory to avoid re-injection - Relaunches Discord via
Start-Processin PowerShell
Reproduce on Your Own VMs
- Locate
%APPDATA%/Discord/discord_desktop_core/index.js - Append a benign
console.logstatement - Relaunch Discord and observe the injected code executing in DevTools
Defensive Countermeasures
- Monitor file integrity of
discord_desktop_core/index.js - Alert on
Discord.exechild processes spawned bynode.exeorwscript.exe - Detect Discord API token queries (
/api/v9/users/@me) from non-browser processes