LWA-2026-11682 confirmed malware

test-in-one@1.0.0

Malicious code in test-in-one (npm)

T1552.001 · Credentials In FilesT1555 · Credentials from Password StoresT1082 · System Information DiscoveryT1005 · Data from Local System

Analysis

The package ships a credential- and wallet-harvesting toolkit under .yalc/detector together with a harvested report from a victim machine. The tool scans desktop wallet directories and browser-extension LevelDB vaults for MetaMask, Phantom, Trust Wallet, Coinbase, Binance, OKX, Rabby, Keplr, TronLink, Ronin, Solflare and Exodus, and extracts secrets from .env and .npmrc files (npm tokens and _authToken values). The bundled report (report-2026-08-28T19-03-15[.]zip) contains a captured MetaMask vault (LevelDB files under the extension id nkbihfbeogaeaoehlefnkodbefgpgknn) and real GitLab personal access tokens (glpat-...) and npm auth tokens from a captured .npmrc.

analyzed by
Leitwacht
first seen
Aug 28, 2026, 07:07 PM
analyzed
Aug 28, 2026, 07:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.