LWA-2026-11799 confirmed malware
telegramxjm@1.0.1
Malicious code in telegramxjm (npm)
T1105 · Ingress Tool TransferT1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
The package ships a FileSaver.js client-side library with an injected userscript beacon appended to the bundle. The injected code reads the running script's metadata and issues a GET request to hxxps://s[.]jtm[.]pub/api/sp/lib (with author/name/version/namespace/updateURL query parameters), then executes the response body via eval(), i.e. a remote code fetch-and-exec loader. It also maintains a daily request counter in persistent storage. The beacon is written against Greasemonkey/Tampermonkey userscript APIs (GM_xmlhttpRequest, GM_getValue, GM_setValue, GM_info).
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 10:46 AM
- analyzed
- Aug 31, 2026, 10:46 AM
Related advisories
- classroomlearning@1.1.0
- opiumisbest@1.1.0
- eslint-prettier-js@0.0.1
- originaldevelopmentstelemetry@1.2.2
- developmentstelemetry@1.0.1
- node-request-utils@1.0.0
- mfaatest@1.0.0
- mfafix@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.