spotify-url-resolvers@3.4.2
Malicious code in spotify-url-resolvers (npm)
Analysis
spotify-url-resolvers is a trojanized package that exfiltrates the installer's project directory to an attacker-controlled Telegram account. When the package is required (index.js runs on require), it zips the entire current working directory — including hidden files such as .env and config — and uploads the archive to Telegram via a hardcoded attacker bot token and chat ID (api[.]telegram[.]org). The package is named after Spotify URL resolution but contains no such functionality; its bundled note.txt instructs victims to add `require('spotify-url-resolvers')` to their code to have "a copy of all the host files" sent to Telegram. Exfiltration target is the Telegram Bot API.
- analyzed by
- Leitwacht
- first seen
- Aug 25, 2026, 02:11 PM
- analyzed
- Aug 25, 2026, 02:11 PM
Related advisories
- spotify-url-infos@3.4.2
- hydration-cls-ui@1.0.0
- auth-otp@1.0.5
- hydration-ui-dim@1.0.0
- evm-validation@1.0.4
- hydration-dim-ui@1.0.0
- mutex-thread@1.3.0
- shared-slot-gate@1.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.