Client modDiscord
Discord client mods, inspected before they load.
A Discord client mod (.plugin.js or theme.css) runs inside the desktop client with full access to your token. Extuno diffs each update and runs it in a sandbox - with vulnerability, secret-leak, static, dynamic, and AI analysis on every scan.
Discord - live inspectionInspecting
BetterFriends 2.4.1
discord mod
2.4.0->2.4.1discord mod
Static
Dynamic
AI
Analyzing update
What Extuno catches in Discord
Evidence, not guesswork.
Each finding names the change, why it is dangerous, and the recommended action.
Diff finding
Token exfiltration
A mod reads the Discord auth token and posts it to an external host.
Critical
Diff finding
Self-bot injection
An update adds code that drives the account without the user.
Critical
Diff finding
Remote theme import
A theme pulls CSS and code from an unlisted origin on load.
Review
See it on a poisoned update
A trusted mod, after one update
Extuno runs the mod in a sandbox and records the chain from load to token theft.
- + Vulnerability and secret-leak testing on every version
- + Static analysis reads the code without running it
- + Dynamic sandbox runs it live and records behavior
- + AI code analysis reads the full source and correlates the change against prior versions
- 1Launch Discord client
- 2Mod loads at startup
- 3Reads auth token
- 4Opens outbound request
- 5Exfiltrates token + DMs
Scan your first Discord plugin free.
Your first 5 credits are free - that is 5 full scans, no card required.