LWA-2026-10986 confirmed malware

developer-dashboard@1.0.2

Malicious code in developer-dashboard (npm)

T1552.001 · Credentials In FilesT1555 · Credentials from Password StoresT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1059.007 · JavaScriptT1082 · System Information Discovery

Analysis

developer-dashboard@1.0.2 is a credential/session stealer ("Stezy Stealer") delivered as a single heavily-obfuscated index.js. On execution it disables TLS certificate verification, uses Windows DPAPI to decrypt browser cookies, and harvests session credentials from Roblox (.ROBLOSECURITY), Instagram (sessionid), Spotify, Steam (ssfn files and config.vdf, uploading the Steam folder to file[.]io), Minecraft (launcher_accounts.json / Lunar Client accounts.json), and Telegram (tdata). Stolen sessions and credentials are exfiltrated to Discord webhooks (discord[.]com) and file[.]io upload endpoints. The package declares a placeholder dependency (your-module-name-here) and has no legitimate functionality.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 01:07 PM
analyzed
Aug 11, 2026, 01:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.