If you can communicate on it, you can abuse it. This was proven again recently when a hacker using the name “scarycoder” uploaded a dozen malicious Python packages to https://pypi.org/, the popular Python code repository. These bits of code pretended to provide useful functions for https://www.roblox.com/ gaming community developers, but all they really did was steal users’ information.
In the battle between ease of use and security, Roblox and Discord err on the side of making their systems too easy to abuse.
Snyk’s researchers state, “This malicious code, known as Discord Injector, can relay an alarming amount of information to the attacker.