LWA-2026-11610 confirmed malware

spotify-url-infos@3.4.2

Malicious code in spotify-url-infos (npm)

T1059.007 · JavaScriptT1005 · Data from Local SystemT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols

Analysis

spotify-url-infos is a trojanized package whose name is unrelated to its function: it is a "server backup" tool that zips the current working directory (including hidden files such as .env) and uploads the archive to a hardcoded Telegram chat every hour. A Telegram bot token and chat ID are hardcoded in src/config.js, so the exfiltrated files (source code, credentials, secrets) are delivered to an attacker-controlled destination rather than the user. The upload runs automatically on start via index.js's hourly loop.

analyzed by
Leitwacht
first seen
Aug 25, 2026, 09:39 AM
analyzed
Aug 25, 2026, 09:39 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.