Serverside

Past work / Security catch — removed a malicious token-stealer

Discord & bots

Security catch — removed a malicious token-stealer

While reviewing the server boot log, I flagged an obfuscated script that turned out to be a Discord token-stealer disguised as a utility — it scanned browser and Discord data and tried to exfiltrate it to a hidden webhook. I removed it from the server immediately and traced the source so it stays out.

What changed

Threat caught and removed before it could compromise anyone; the client server cleaned and secured.

Done for Nueva Vida RP.