LWA-2026-11723 confirmed malware

test__123q1@2.1.3

Malicious code in test__123q1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1555 · Credentials from Password StoresT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (node dist/script.js) is a credential-harvesting, self-propagating worm. On install it scans the victim's machine for desktop crypto wallets (Exodus, Atomic, Electrum, Bitcoin Core, Guarda, Coinomi, Jaxx, Ledger Live, Trezor, Wasabi, Sparrow), browser-extension wallet data (MetaMask, Phantom, Trust, Coinbase, Binance, OKX, Rabby, Keplr, TronLink, Ronin, Solflare, Exodus), sensitive files (.env, .npmrc, .yarnrc, .git-credentials, .gitconfig, credentials.json, aws/gcloud/firebase service accounts, id_rsa/id_ed25519 private keys, config.json), SSH private keys, AWS credentials, and environment variables whose names contain pass/pwd/secret/token/key/auth/mnemonic/seed/npm. It zips the collected report and exfiltrates it to a hardcoded Telegram bot via hxxps://api[.]telegram[.]org/bot<token>/sendDocument (chat_id 416517694). It then uses any harvested npm token to query the npm registry for packages the victim maintains, downloads each tarball, injects this same script as a postinstall hook, bumps the version, and re-publishes the trojanized package under the victim's identity, propagating itself across the victim's package ecosystem.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 11:40 AM
analyzed
Aug 29, 2026, 11:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.