LWA-2026-11610 confirmed malware
spotify-url-infos@3.4.2
Malicious code in spotify-url-infos (npm)
T1059.007 · JavaScriptT1005 · Data from Local SystemT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols
Analysis
spotify-url-infos is a trojanized package whose name is unrelated to its function: it is a "server backup" tool that zips the current working directory (including hidden files such as .env) and uploads the archive to a hardcoded Telegram chat every hour. A Telegram bot token and chat ID are hardcoded in src/config.js, so the exfiltrated files (source code, credentials, secrets) are delivered to an attacker-controlled destination rather than the user. The upload runs automatically on start via index.js's hourly loop.
- analyzed by
- Leitwacht
- first seen
- Aug 25, 2026, 09:39 AM
- analyzed
- Aug 25, 2026, 09:39 AM
Related advisories
- hydration-cls-ui@1.0.0
- auth-otp@1.0.5
- hydration-ui-dim@1.0.0
- evm-validation@1.0.4
- hydration-dim-ui@1.0.0
- mutex-thread@1.3.0
- shared-slot-gate@1.1.2
- async-critical-section@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.