LWA-2026-11595 confirmed malware

auth-otp@1.0.5

Malicious code in auth-otp (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information Discovery

Analysis

auth-otp@1.0.5 is a credential-stealing infostealer disguised as a TOTP/HOTP library. Its postinstall hook runs lib/core.js, which harvests Minecraft account tokens (access tokens, MSA refresh tokens, Modrinth PATs) from Vanilla/Lunar/Essential/CurseForge/Modrinth launcher files, and Discord tokens from Discord/Chrome/Edge/Brave/Opera local storage (decrypting encrypted tokens via DPAPI + AES-GCM). All stolen credentials are exfiltrated to a Discord webhook at discord[.]com/api/webhooks/1532429233769419004/VE9zx782_hy5vedls0lwNRAVA1sUGb9Q2chTdXdrcmXuNzztkeXe7Ilbt36OjWaNnTXe. The hook also downloads and installs a jar from github[.]com/ghysghqgHUJ/.jar/releases/download/v1.0.0/fabric-api-boost-1.0.0.jar into Minecraft mods folders. The code checks for CI/sandbox/audit environments and exits without running there.

analyzed by
Leitwacht
first seen
Aug 24, 2026, 12:48 PM
analyzed
Aug 24, 2026, 12:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.