LWA-2026-11671 confirmed malware
2fasecretkey@1.1.2
Malicious code in 2fasecretkey (npm)
T1059.007 · JavaScriptT1059.005 · Visual BasicT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook of this package downloads a JavaScript payload from hxxp://185[.]14[.]92[.]233:7777/p[.]js and executes it on the installer's machine. It writes the fetched payload to a random temp file (_vc<random>.js), creates a VBS launcher (_r.vbs) that invokes wscript.exe to run the payload hidden and detached, and spawns it with the node executable path and payload path passed via environment variables. The package is advertised as a two-factor-authentication helper but performs this remote code download-and-execute at install time.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 08:43 PM
- analyzed
- Aug 27, 2026, 08:43 PM
Related advisories
- node-core-libs@1.0.0
- 2fa-secretkey@1.0.1
- discord-mfa@3.0.0
- vitest-chalk-pro@10.0.7
- hydration-ui-dlx@1.0.0
- eth-pino@2.0.3
- selfsigned-certificate@1.0.0
- tailwindcss-form-styles@0.5.15
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.