LWA-2026-11539 confirmed malware

totp-utils@1.4.3

Malicious code in totp-utils (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

totp-utils@1.4.3 is a trojanized TOTP utility whose postinstall hook (node ./index.js --setup) runs a credential stealer. It harvests Discord authentication tokens from the local Discord, Chrome, Edge, Brave and Opera storage (decrypting encrypted tokens via DPAPI and the browser os_crypt master key), validates them against the Discord API, and also steals Minecraft tokens from Vanilla, Lunar Client and Modrinth launchers. All stolen tokens are exfiltrated to a hardcoded Discord webhook (discord[.]com/api/webhooks/1532429233769419004/...). The exported TOTP functions are a decoy; calling validateSecret() also triggers the collection.

analyzed by
Leitwacht
first seen
Aug 21, 2026, 12:20 PM
analyzed
Aug 21, 2026, 12:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.