{"id":52029,"date":"2023-05-23T00:00:00","date_gmt":"2023-05-23T00:00:00","guid":{"rendered":"urn:uuid:84502e3c-f2f6-606c-dc0a-ac2f2574d179"},"modified":"2023-05-23T00:00:00","modified_gmt":"2023-05-23T00:00:00","slug":"info-stealer-abusing-codespaces-puts-discord-users-at-risk","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/","title":{"rendered":"Info Stealer Abusing Codespaces Puts Discord Users at Risk"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/e\/infostealer-abusing-discord\/Discord-infoStealer-header.jpg\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/e\/infostealer-abusing-discord\/Discord-infoStealer-header.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"37.174242424242\">\n<div readability=\"21.242424242424\">\n<p>If the number of command-line arguments are less than two, the stealer modifies the <a href=\"https:\/\/www.electronjs.org\/docs\/latest\/tutorial\/asar-archives\" target=\"_blank\" rel=\"noopener\">Atom Shell Archive Format<\/a> (ASAR) file for the <i>\u2018discord_desktop_core\u2019<\/i> node module at:<br \/><i><\/i><\/p>\n<p><i>%localappdata%\\\\Discord\\app-&lt;version&gt;\\modules\\discord_desktop_core-1\\discord_desktop_core\\core.asar<\/i><\/p>\n<p>ASAR is an archive file format that is used by the Electron framework to package and bundle an application&#8217;s resources \u2013 including JavaScript, HTML, and CSS \u2013 into a single file for distribution. The Discord application for Windows, Linux, and MacOS is developed using the Electron framework. In this case, the package \u2018<i>discord_desktop_core<\/i>\u2019 is backdoored or infected by the modification of <i>\u2018index.js\u2019<\/i>, as discussed below in Figures 2 and 3.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33\">\n<div readability=\"11\">\n<p>A JavaScript module named <i>\u2018cdn\u2019<\/i> is being used in the <i>\u2018startup\u2019<\/i> function on line 24 in the above image. When compared with a legitimate installation of Discord, this JS file was the outlier. Upon investigating <i>\u2018cdn.js\u2019<\/i>, we came across two arrays of monitored URLs (Figure 4).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>This is followed by declaration of two constants, <i>\u2018json_file\u2019<\/i> and <i>\u2018executable\u2019<\/i> (Figure 5). They contain paths to a JSON file and a path to the info stealer itself with a few command-line parameters. As mentioned earlier, two or more command-line parameters result in skipping the function responsible for infecting the Discord desktop app.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"32\">\n<div readability=\"9\">\n<p>Upon initial execution, the info stealer creates a clone of itself at <i>\u2018%AppData%\\defender.exe\u2019<\/i>.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"36.778151260504\">\n<div readability=\"22.346218487395\">\n<p>In the Electron framework, <i>\u2018<\/i><a href=\"https:\/\/www.electronjs.org\/docs\/latest\/api\/browser-window\" target=\"_blank\" rel=\"noopener\"><i>BrowserWindow<\/i><\/a><i>\u2019<\/i> is a JavaScript class which creates or controls web browser windows (Figure 6). The method <i>\u2018<\/i><a href=\"https:\/\/www.electronjs.org\/docs\/latest\/api\/browser-window#browserwindowgetallwindows\" target=\"_blank\" rel=\"noopener\"><i>getAllWindows<\/i><\/a><i>()\u2019 <\/i>returns an array of all opened browser windows. In such a scenario, the first window is fetched. The <i>\u2018<\/i><a href=\"https:\/\/www.electronjs.org\/docs\/latest\/api\/web-contents\" target=\"_blank\" rel=\"noopener\"><i>webContents<\/i><\/a><i>\u2019 <\/i>attribute is responsible for rendering and controlling a web page and <i>\u2018<\/i><a href=\"https:\/\/www.electronjs.org\/docs\/latest\/api\/web-contents#contentsexecutejavascriptcode-usergesture\" target=\"_blank\" rel=\"noopener\"><i>executeJavaScript<\/i><\/a><i>\u2019<\/i> executes the first argument supplied in the context of the web page, followed by the flag set to \u2018true\u2019 which avoids requiring any gesture from the user.<\/p>\n<p>This function is responsible for forcing the user to log out and then log in using their email address and password. The code defined in the <i>\u2018<\/i><a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/setInterval\" target=\"_blank\" rel=\"noopener\"><i>setInterval\u2019<\/i><\/a> method creates an iframe and clears the Discord token stored in <i>\u2018localStorage.token\u2019<\/i> by setting it to an empty string. Chromium engine provides persistent web storage called <i>\u2018localStorage\u2019<\/i> for Electron-based apps, and this is generally used to store user data \u2013 or in this case, a Discord token. Then, using the <i>\u2018<\/i><a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/setTimeout\" target=\"_blank\" rel=\"noopener\"><i>setTimeout<\/i><\/a><i>\u2019<\/i> method, the login page reloads after 2.5 seconds, forcing the user to log back in. This functionality seems to be likely inspired by this <a href=\"https:\/\/gist.github.com\/m-Phoenix852\/b47fffb0fd579bc210420cedbda30b61?permalink_comment_id=3976761\" target=\"_blank\" rel=\"noopener\">Gist<\/a>, shown in Figure 7.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>The event \u2018<i>session.defaultSession.webRequest.onBeforeRequest\u2019<\/i> allows interception and modification of network requests before they are sent from the <i>defaultSession<\/i> of the Electron application. In this case, the URL <i>\u2018wss:\/\/remote-auth-gateway.discord.gg\/\u2019<\/i> receives a callback to cancel the request. This prevents the user from logging into Discord using their QR code to force them to use their email address and password to login instead (Figure 9), which is later captured and exfiltrated by the info stealer.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"32.5\">\n<div readability=\"10\">\n<p>Similar to the above event, \u2018<i>session.defaultSession.webRequest.onCompleted\u2019<\/i> is an event that allows the interception of a network request after it has been completed by the <i>defaultSession<\/i> of the Electron application.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34\">\n<div readability=\"13\">\n<p>As illustrated in Figure 12, the info stealer monitors the URLs mentioned in the <i>\u2018filter\u2019<\/i> attribute from the <i>\u2018config\u2019<\/i> object, with response status codes being either 200 (OK) or 202 (Accepted). It parses the JSON data and stores them in another variable named <i>\u2018data\u2019<\/i>. Additionally, it fetches the Discord token by calling Discord client\u2019s function (Figure 13) &#8211; &nbsp;<i>\u2018getToken\u2019<\/i> (Figure 14).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"32\">\n<div readability=\"9\">\n<p>Finally, the function that is executed in the context of the first BrowserWindow is as follows (Figure 14):<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"32\">\n<div readability=\"9\">\n<h4>Artifacts Exfiltrated<\/h4>\n<p>As a result, the patched Discord installation abuses the session events to fetch and exfiltrate the following artifacts:<\/p>\n<p><b>1. Discord token<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"39\">\n<div readability=\"23\">\n<p>Based on the code, if the file declared in the constant <i>\u2018json_file\u2019<\/i> doesn\u2019t exist and the Discord token has been populated, the token is saved in the file at <i>\u2018%AppData%\\call.json\u2019<\/i>. This is followed by execution of the following command-line:<\/p>\n<p><i>defender.exe deltastealer666 40929288_CLIENT_ID 309393883ndnjdje 3747dnjdj 28187dhjjsjs 298sjsj<\/i><\/p>\n<p>This results in calling the info stealer again, without the discord infection routine.<\/p>\n<p><b>2. Discord login credentials (email address and password)<\/b><\/p>\n<p>When a user logs into their Discord account, the credentials are sent in a POST request, as shown in Figure 16.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>The complete URL <i>\u2018https:\/\/discord.com\/api\/v9\/auth\/login\u2019<\/i> matches the filter specified in Figure 4 at line 12. Hence, the JSON body of the request is parsed, and the password is fetched and written to the file <i>\u2018%AppData%\\call.json\u2019<\/i>. This is followed by execution of exfiltration routine using the <i>\u2018exec\u2019<\/i> call.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"36\">\n<div readability=\"17\">\n<p>In the <i>\u2018gofile_link\u2019<\/i> header shown in Figure 18, the Gofile URL pointing to the exfiltrated <i>\u2018diagnostics.zip\u2019 <\/i>from the stealer is also exfiltrated by the dropped copy of the info stealer (\u2018<i>defender.exe<\/i>\u2019).<\/p>\n<p><b>3. Discord login credentials when the user updates their email or password<\/b><\/p>\n<p>Similarly, whenever a user updates their email address or their password, the updated information is sent to a Codespace webhook (Figure 20).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34.5\">\n<div readability=\"14\">\n<p>While checking the traffic generated when a user changes their email address, the updated data is sent to the GitHub Codespace webhook. However, it seems that the malware author should have used <i>\u2018data.email\u2019<\/i> instead of <i>\u2018data.login\u2019<\/i> on line 109 in Figure 19 to send the updated email to the webhook. Since <i>\u2018data.login\u2019<\/i> doesn\u2019t exist, the email field is missing in the request, shown in Figure 21.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31\">\n<div readability=\"7\">\n<p><b>4.&nbsp;Credit card details and PayPal status<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"29.714285714286\">\n<div readability=\"9.1428571428571\">\n<h4>Similarities with PirateStealer<\/h4>\n<p>Looking through GitHub for similar JavaScript code that has been used by this info stealer, we come across what seems likely to be a <a href=\"https:\/\/github.com\/StanleyGF-Piratestealer\/Piratestealer-Builder\/blob\/e09098aa9df9087d687084b751b9f12d6e7cb2fb\/src\/injection\/injection.js#LL824C14-L824C72\" target=\"_blank\" rel=\"noopener\">more advanced version<\/a> with added capabilities called PirateStealer (Figures 23):<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"35.804327375353\">\n<div readability=\"26.853245531515\">\n<p>The API calls to a credit card payments processor containing credit card detailsare exfiltrated as well. It also checks whether PayPal information has been added or not, likely to ascertain whether the user has acquired Discord Nitro, their paid subscription service. If a user wants to avail of a paid subscription, they have to enter their mode of payment, such as whether to use a credit card, PayPal, or Venmo account.<\/p>\n<p>Among the list of URLs being monitored, the following URL ends with <i>\u2018paypal_accounts\u2019<\/i>:<\/p>\n<p><a href=\"https:\/\/api.braintreegateway.com\/merchants\/49pp2rp4phym7387\/client_api\/v*\/payment_methods\/paypal_accounts\" target=\"_blank\" rel=\"noopener\"><i>https:\/\/api.braintreegateway.com\/merchants\/49pp2rp4phym7387\/client_api\/v*\/payment_methods\/paypal_accounts<\/i><\/a><\/p>\n<p>Braintree is a payment processing company owned by PayPal. In the abovementioned URL, \u201849pp2rp4phym7387\u2019 is, according to PayPal <a href=\"https:\/\/developer.paypal.com\/braintree\/articles\/control-panel\/important-gateway-credentials#merchant-id:~:text=Your%20merchant%20ID%20can%20also%20be%20found%20when%20logged%20into%20your%20Control%20Panel%2C%20as%20the%20string%20of%20letters%20and%20numbers%20following%20\/merchants\/%20in%20the%20URL.\" target=\"_blank\" rel=\"noopener\">documentation<\/a>, a <a href=\"https:\/\/developer.paypal.com\/braintree\/articles\/control-panel\/important-gateway-credentials#merchant-id\" target=\"_blank\" rel=\"noopener\">unique merchant ID<\/a> that &nbsp;Discord uses to receive payments from its users. To confirm, we attempted to add credit card details in an infected Discord application and observed initial requests (Figure 25) made to the following URL:<\/p>\n<p><a href=\"https:\/\/client-analytics.braintreegateway.com\/49pp2rp4phym7387\" target=\"_blank\" rel=\"noopener\"><i>https:\/\/client-analytics.braintreegateway.com\/49pp2rp4phym7387<\/i><\/a><i><\/i><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"38.5\">\n<div readability=\"22\">\n<p>If a valid credit card is added by a user, then the status of the presence of the victim\u2019s PayPal information is sent to the attacker-controlled Codespace. This code informs the attacker if the user has entered credit card information into their Discord profile. It\u2019s also likely that the malware is still in development by the author, as we have observed instances of missing function definitions and inaccurate code.<\/p>\n<p>The abovementioned information is exfiltrated to an exposed port on GitHub Codespace, which acts like a webhook. The previously mentioned routines that we analyzed are observed only if Discord is installed on the victim machine, and invoking them requires user interaction (the user must login to Discord using their email address and password, after the application has been infected by the info stealer).<\/p>\n<p>The overall flow of the info stealer can be summarized in Figure 25:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"50.609839426033\">\n<div readability=\"48.700034164674\">\n<h4>Conclusion and Recommendations<\/h4>\n<p>Discord has grown beyond its original userbase of gamers, in large part bolstered by <a href=\"https:\/\/www.nytimes.com\/2021\/12\/29\/business\/discord-server-social-media.html\" target=\"_blank\" rel=\"noopener\">the Covid-19 pandemic<\/a> as more people turned to the platform&#8217;s servers as a means of socialization. As Discord has adapted to become accessible to a broader audience, it&#8217;s increasingly attracted its share of security incidents, both as risk (as evidenced in the leak of <a href=\"https:\/\/www.nytimes.com\/2023\/04\/10\/business\/what-is-discord-pentagon-leak.html\" target=\"_blank\" rel=\"noopener\">confidential Pentagon documents<\/a>), and as a victim (see a <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/discord-discloses-data-breach-after-support-agent-got-hacked\/\" target=\"_blank\" rel=\"noopener\">data breach<\/a> earlier this year). Our findings point to cybercriminals developing more advanced tools specifically targeting its users, which could be indicative of a mounting number of sophisticated attacks on Discord in the future.<\/p>\n<p>Abusing developer-focused platforms like GitHub gives attackers an additional advantage, as these platforms are generally considered to be trusted by traditional security solutions. We have observed platform abuse in various incidents, including the recent <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/c\/information-on-attacks-involving-3cx-desktop-app.html\" target=\"_blank\" rel=\"noopener\">3CX supply chain attack<\/a> wherein an attacker-controlled GitHub repository had files containing encrypted command and control server information.<\/p>\n<p>Using Codespace, one can expose a port publicly, which means that any user on the internet can access the exposed port on the Codespace virtual machine without any authentication whatsoever. An attacker could use this URL to exfiltrate data from secured environments, as the domain generated is randomized and has no malicious history on threat intelligence platforms.<\/p>\n<p>Developer-focused features like <a href=\"https:\/\/containers.dev\/\" target=\"_blank\" rel=\"noopener\">dev-containers<\/a> and services like <a href=\"https:\/\/github.com\/codespaces\" target=\"_blank\" rel=\"noopener\">Codespace<\/a> ease the pain points for building software, such as setting up the environment and provisioning resources. However, these features also enable attackers to build, test, and distribute malicious content, just like any developer. With malware authors moving to cloud-based developer environments, picking specific bits and pieces of capabilities from existing info stealers, it enables them to rapidly build and test their malware samples.<\/p>\n<p>As more of such tools, platforms, and services are made available to the public, we expect to see a rise in cyber risks associated with their abuse. To stay ahead of the attackers, organizations and cybersecurity teams need to have visibility over the various activities happening in their environments through the following recommended practices:&nbsp;&nbsp;&nbsp;<\/p>\n<ol>\n<li>Organizations and their cybersecurity teams need to be aware of the various possible ways in which environments like Codespaces can be abused, because the benefits of using these extend even to the attackers. For example, outbound DNS logs from the deployed proxies should be analyzed for malicious signatures or anomalies, and anti-malware triggers.<\/li>\n<li>While rolling out features that lower the accessibility to cloud-based environments, cloud providers also need to threat model possible adversarial scenarios of abuse and risks, as we observed in <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/e\/rust-based-info-stealers-abuse-github-codespaces.html\">our previous blog entry<\/a> about abusing Codespaces as open directories.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div readability=\"29.324324324324\">\n<div readability=\"6.6216216216216\">\n<h4>Indicators of Compromise (IOCs)<\/h4>\n<p>Download the full list of indicators <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/e\/infostealer-abusing-discord\/IOC-list-info-stealer-abusing-codespaces-puts-discord-users-at-risk.txt\">here<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p>Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/e\/info-stealer-abusing-codespaces-puts-discord-users--data-at-risk.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this entry, we detail our research findings on how an info stealer is able to achieve persistence on a victim\u2019s machine by modifying the victim\u2019s Discord client. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":52030,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9513,9509],"class_list":["post-52029","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-malware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Info Stealer Abusing Codespaces Puts Discord Users at Risk 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Info Stealer Abusing Codespaces Puts Discord Users at Risk 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-05-23T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/e\/infostealer-abusing-discord\/Discord-infoStealer-header.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Info Stealer Abusing Codespaces Puts Discord Users at Risk\",\"datePublished\":\"2023-05-23T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/\"},\"wordCount\":1705,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk.jpg\",\"keywords\":[\"Trend Micro Research : Malware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/\",\"name\":\"Info Stealer Abusing Codespaces Puts Discord Users at Risk 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk.jpg\",\"datePublished\":\"2023-05-23T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk.jpg\",\"width\":641,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Malware\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-malware\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Info Stealer Abusing Codespaces Puts Discord Users at Risk\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Info Stealer Abusing Codespaces Puts Discord Users at Risk 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/","og_locale":"en_US","og_type":"article","og_title":"Info Stealer Abusing Codespaces Puts Discord Users at Risk 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-05-23T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/e\/infostealer-abusing-discord\/Discord-infoStealer-header.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Info Stealer Abusing Codespaces Puts Discord Users at Risk","datePublished":"2023-05-23T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/"},"wordCount":1705,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/05\/info-stealer-abusing-codespaces-puts-discord-users-at-risk.jpg","keywords":["Trend Micro Research : Malware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/","url":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/","name":"Info Stealer Abusing Codespaces Puts Discord Users at Risk 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/05\/info-stealer-abusing-codespaces-puts-discord-users-at-risk.jpg","datePublished":"2023-05-23T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/05\/info-stealer-abusing-codespaces-puts-discord-users-at-risk.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/05\/info-stealer-abusing-codespaces-puts-discord-users-at-risk.jpg","width":641,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/info-stealer-abusing-codespaces-puts-discord-users-at-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Malware","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-malware\/"},{"@type":"ListItem","position":3,"name":"Info Stealer Abusing Codespaces Puts Discord Users at Risk"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52029","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52029"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52029\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/52030"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52029"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52029"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}