test__123q1@2.1.3
Malicious code in test__123q1 (npm)
Analysis
The postinstall hook (node dist/script.js) is a credential-harvesting, self-propagating worm. On install it scans the victim's machine for desktop crypto wallets (Exodus, Atomic, Electrum, Bitcoin Core, Guarda, Coinomi, Jaxx, Ledger Live, Trezor, Wasabi, Sparrow), browser-extension wallet data (MetaMask, Phantom, Trust, Coinbase, Binance, OKX, Rabby, Keplr, TronLink, Ronin, Solflare, Exodus), sensitive files (.env, .npmrc, .yarnrc, .git-credentials, .gitconfig, credentials.json, aws/gcloud/firebase service accounts, id_rsa/id_ed25519 private keys, config.json), SSH private keys, AWS credentials, and environment variables whose names contain pass/pwd/secret/token/key/auth/mnemonic/seed/npm. It zips the collected report and exfiltrates it to a hardcoded Telegram bot via hxxps://api[.]telegram[.]org/bot<token>/sendDocument (chat_id 416517694). It then uses any harvested npm token to query the npm registry for packages the victim maintains, downloads each tarball, injects this same script as a postinstall hook, bumps the version, and re-publishes the trojanized package under the victim's identity, propagating itself across the victim's package ecosystem.
- analyzed by
- Leitwacht
- first seen
- Aug 29, 2026, 11:40 AM
- analyzed
- Aug 29, 2026, 11:40 AM
Related advisories
- test-in-one@1.0.0
- developer-dashboard@1.0.2
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-kit-map@1.0.0
- streak-calc-math@1.0.0
- streak-metrics-core@1.0.0
- system-performance-helper@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.