LWA-2026-0232 confirmed malware

@digininja/key_stealer@1.0.1

Malicious code in @digininja/key_stealer (npm)

Analysis

The package (named 'key_stealer') is a credential-theft payload. Its postinstall hook reads the MY_SECRET_API_KEY environment variable, base64-encodes it, and exfiltrates it via a fetch request to a requestcatcher[.]com collector endpoint.

analyzed by
Leitwacht
first seen
May 27, 2026, 05:29 AM
analyzed
May 27, 2026, 05:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.