LWA-2026-0233 confirmed malware
@digininja/key_stealer@1.0.2
Malicious code in @digininja/key_stealer (npm)
Analysis
Postinstall hook (setup.js) reads MY_SECRET_API_KEY from the environment, base64-encodes it, and exfiltrates it via HTTP to digininja[.]requestcatcher[.]com. A secondary exfiltration channel in dns_callback.js uses DNS tunneling to collab[.]digi[.]ninja. Credential theft with multiple exfiltration channels.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 05:29 AM
- analyzed
- May 27, 2026, 05:30 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.