LWA-2026-11613 confirmed malware

spotify-url-resolvers@3.4.2

Malicious code in spotify-url-resolvers (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1560 · Archive Collected DataT1071.001 · Web ProtocolsT1567 · Exfiltration Over Web Service

Analysis

spotify-url-resolvers is a trojanized package that exfiltrates the installer's project directory to an attacker-controlled Telegram account. When the package is required (index.js runs on require), it zips the entire current working directory — including hidden files such as .env and config — and uploads the archive to Telegram via a hardcoded attacker bot token and chat ID (api[.]telegram[.]org). The package is named after Spotify URL resolution but contains no such functionality; its bundled note.txt instructs victims to add `require('spotify-url-resolvers')` to their code to have "a copy of all the host files" sent to Telegram. Exfiltration target is the Telegram Bot API.

analyzed by
Leitwacht
first seen
Aug 25, 2026, 02:11 PM
analyzed
Aug 25, 2026, 02:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.