Client modDiscord

Discord loads its mods at startup. Extuno scans them first.

A Discord client mod (.plugin.js or theme.css) runs inside the desktop client with full access to your token. Extuno diffs each update and runs the mod in a sandbox. Five checks on every scan: vulnerability, secret-leak, static, dynamic, and AI analysis.

In shortTo check a Discord plugin for supply-chain risk, scan the published artifact, not just the source, and compare each new version against the last. Extuno runs static analysis, a dynamic sandbox, and AI review across every Discord release, then reports evidence on every finding.
Discord - live inspectionexample
acme-friend-tools 2.4.1
discord mod
2.4.0->2.4.1
Static
Dynamic
AI
Analyzing update
What Extuno catches in Discord

Every finding is backed by evidence.

Each finding names the change, why it is dangerous, and the recommended action.

Diff finding

Token exfiltration

A mod reads the Discord auth token and posts it to an external host.

Critical
Diff finding

Self-bot injection

An update adds code that drives the account without the user.

Critical
Diff finding

Remote theme import

A theme pulls CSS and code from an unlisted origin on load.

Review
See it on a poisoned update

A trusted mod, after one update

Extuno runs the mod in a sandbox and records the chain from load to token theft.

  • + Vulnerability and secret-leak testing on every version
  • + Static analysis reads the code without running it
  • + Dynamic sandbox runs it live and records behavior
  • + AI code analysis reads the full source and correlates the change against prior versions
How it works
  1. 1Launch Discord client
  2. 2Mod loads at startup
  3. 3Reads auth token
  4. 4Opens outbound request
  5. 5Exfiltrates token + DMs

Scan your first Discord plugin free.

5 free credits on signup. One credit per scan, no card required.

FAQ

Common questions

Does Extuno support Discord?

Yes. Extuno scans Discord with static analysis, a dynamic sandbox, and AI code analysis, and diffs every version to catch one that was clean but poisoned through an update.

How does Extuno scan Discord?

Extuno acquires the published Discord artifact, reads it statically with 1100+ rules, runs it in a network-segmented sandbox, reviews the source with AI, and diffs it against the prior version. The finding names the file, the change, why it is dangerous, and the fix.

What does Extuno catch in Discord?

Leaked secrets, obfuscated or malicious code, dangerous permissions and APIs, exfiltration and command-and-control behavior, and the headline signal: a version that turns malicious after an update.