test-in-one@1.0.0
Malicious code in test-in-one (npm)
Analysis
The package ships a credential- and wallet-harvesting toolkit under .yalc/detector together with a harvested report from a victim machine. The tool scans desktop wallet directories and browser-extension LevelDB vaults for MetaMask, Phantom, Trust Wallet, Coinbase, Binance, OKX, Rabby, Keplr, TronLink, Ronin, Solflare and Exodus, and extracts secrets from .env and .npmrc files (npm tokens and _authToken values). The bundled report (report-2026-08-28T19-03-15[.]zip) contains a captured MetaMask vault (LevelDB files under the extension id nkbihfbeogaeaoehlefnkodbefgpgknn) and real GitLab personal access tokens (glpat-...) and npm auth tokens from a captured .npmrc.
- analyzed by
- Leitwacht
- first seen
- Aug 28, 2026, 07:07 PM
- analyzed
- Aug 28, 2026, 07:07 PM
Related advisories
- developer-dashboard@1.0.2
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-kit-map@1.0.0
- streak-calc-math@1.0.0
- streak-metrics-core@1.0.0
- system-performance-helper@1.0.1
- quickbuf@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.