LWA-2026-11664 confirmed malware
2fa-secretkey@1.0.1
Malicious code in 2fa-secretkey (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook of this TOTP helper package downloads a script from hxxp://185[.]14[.]92[.]233:7777/p[.]js over plain HTTP and executes it immediately via the JavaScript Function constructor. The package's main index.js is a decoy TOTP wrapper that references a lib/core module which is not shipped in the tarball. Installing the package runs the remote downloader, giving the remote host arbitrary code execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 07:00 PM
- analyzed
- Aug 27, 2026, 07:00 PM
Related advisories
- discord-mfa@3.0.0
- vitest-chalk-pro@10.0.7
- hydration-ui-dlx@1.0.0
- eth-pino@2.0.3
- selfsigned-certificate@1.0.0
- tailwindcss-form-styles@0.5.15
- tailwindcss-3d-animate@1.2.2
- htps-provider@1.0.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.