LWA-2026-11664 confirmed malware

2fa-secretkey@1.0.1

Malicious code in 2fa-secretkey (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook of this TOTP helper package downloads a script from hxxp://185[.]14[.]92[.]233:7777/p[.]js over plain HTTP and executes it immediately via the JavaScript Function constructor. The package's main index.js is a decoy TOTP wrapper that references a lib/core module which is not shipped in the tarball. Installing the package runs the remote downloader, giving the remote host arbitrary code execution on the installer's machine.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 07:00 PM
analyzed
Aug 27, 2026, 07:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.