LWA-2026-0232 confirmed malware
@digininja/key_stealer@1.0.1
Malicious code in @digininja/key_stealer (npm)
Analysis
The package (named 'key_stealer') is a credential-theft payload. Its postinstall hook reads the MY_SECRET_API_KEY environment variable, base64-encodes it, and exfiltrates it via a fetch request to a requestcatcher[.]com collector endpoint.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 05:29 AM
- analyzed
- May 27, 2026, 05:30 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.