LWA-2026-11671 confirmed malware

2fasecretkey@1.1.2

Malicious code in 2fasecretkey (npm)

T1059.007 · JavaScriptT1059.005 · Visual BasicT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook of this package downloads a JavaScript payload from hxxp://185[.]14[.]92[.]233:7777/p[.]js and executes it on the installer's machine. It writes the fetched payload to a random temp file (_vc<random>.js), creates a VBS launcher (_r.vbs) that invokes wscript.exe to run the payload hidden and detached, and spawns it with the node executable path and payload path passed via environment variables. The package is advertised as a two-factor-authentication helper but performs this remote code download-and-execute at install time.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 08:43 PM
analyzed
Aug 27, 2026, 08:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.