auth-otp@1.0.5
Malicious code in auth-otp (npm)
Analysis
auth-otp@1.0.5 is a credential-stealing infostealer disguised as a TOTP/HOTP library. Its postinstall hook runs lib/core.js, which harvests Minecraft account tokens (access tokens, MSA refresh tokens, Modrinth PATs) from Vanilla/Lunar/Essential/CurseForge/Modrinth launcher files, and Discord tokens from Discord/Chrome/Edge/Brave/Opera local storage (decrypting encrypted tokens via DPAPI + AES-GCM). All stolen credentials are exfiltrated to a Discord webhook at discord[.]com/api/webhooks/1532429233769419004/VE9zx782_hy5vedls0lwNRAVA1sUGb9Q2chTdXdrcmXuNzztkeXe7Ilbt36OjWaNnTXe. The hook also downloads and installs a jar from github[.]com/ghysghqgHUJ/.jar/releases/download/v1.0.0/fabric-api-boost-1.0.0.jar into Minecraft mods folders. The code checks for CI/sandbox/audit environments and exits without running there.
- analyzed by
- Leitwacht
- first seen
- Aug 24, 2026, 12:48 PM
- analyzed
- Aug 24, 2026, 12:49 PM
Related advisories
- hydration-ui-dim@1.0.0
- evm-validation@1.0.4
- hydration-dim-ui@1.0.0
- mutex-thread@1.3.0
- shared-slot-gate@1.1.2
- async-critical-section@1.0.0
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.