LWA-2026-0233 confirmed malware

@digininja/key_stealer@1.0.2

Malicious code in @digininja/key_stealer (npm)

Analysis

Postinstall hook (setup.js) reads MY_SECRET_API_KEY from the environment, base64-encodes it, and exfiltrates it via HTTP to digininja[.]requestcatcher[.]com. A secondary exfiltration channel in dns_callback.js uses DNS tunneling to collab[.]digi[.]ninja. Credential theft with multiple exfiltration channels.

analyzed by
Leitwacht
first seen
May 27, 2026, 05:29 AM
analyzed
May 27, 2026, 05:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.