totp-utils@1.4.3
Malicious code in totp-utils (npm)
Analysis
totp-utils@1.4.3 is a trojanized TOTP utility whose postinstall hook (node ./index.js --setup) runs a credential stealer. It harvests Discord authentication tokens from the local Discord, Chrome, Edge, Brave and Opera storage (decrypting encrypted tokens via DPAPI and the browser os_crypt master key), validates them against the Discord API, and also steals Minecraft tokens from Vanilla, Lunar Client and Modrinth launchers. All stolen tokens are exfiltrated to a hardcoded Discord webhook (discord[.]com/api/webhooks/1532429233769419004/...). The exported TOTP functions are a decoy; calling validateSecret() also triggers the collection.
- analyzed by
- Leitwacht
- first seen
- Aug 21, 2026, 12:20 PM
- analyzed
- Aug 21, 2026, 12:20 PM
Related advisories
- kit-map-vim@1.0.0
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- streak-cache-map@1.0.0
- streak-math-calc@1.0.0
- approval-guardian@1.0.8
- @bobfrankston/rmfmail@1.2.211
- streak-metrics-math@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.