When Discord is started, it loads a file named inject. … Once a victim logs in, the modified Discord client disables 2FA on their account, and sends the user’s email address, user token, login name, plain text password, and IP address to a Discord channel under the attacker’s control.