developer-dashboard@1.0.2
Malicious code in developer-dashboard (npm)
Analysis
developer-dashboard@1.0.2 is a credential/session stealer ("Stezy Stealer") delivered as a single heavily-obfuscated index.js. On execution it disables TLS certificate verification, uses Windows DPAPI to decrypt browser cookies, and harvests session credentials from Roblox (.ROBLOSECURITY), Instagram (sessionid), Spotify, Steam (ssfn files and config.vdf, uploading the Steam folder to file[.]io), Minecraft (launcher_accounts.json / Lunar Client accounts.json), and Telegram (tdata). Stolen sessions and credentials are exfiltrated to Discord webhooks (discord[.]com) and file[.]io upload endpoints. The package declares a placeholder dependency (your-module-name-here) and has no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 01:07 PM
- analyzed
- Aug 11, 2026, 01:10 PM
Related advisories
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-kit-map@1.0.0
- streak-calc-math@1.0.0
- streak-metrics-core@1.0.0
- system-performance-helper@1.0.1
- quickbuf@1.0.1
- @wagni_bot/orca-sdk@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.