LWA-2026-11799 confirmed malware

telegramxjm@1.0.1

Malicious code in telegramxjm (npm)

T1105 · Ingress Tool TransferT1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

The package ships a FileSaver.js client-side library with an injected userscript beacon appended to the bundle. The injected code reads the running script's metadata and issues a GET request to hxxps://s[.]jtm[.]pub/api/sp/lib (with author/name/version/namespace/updateURL query parameters), then executes the response body via eval(), i.e. a remote code fetch-and-exec loader. It also maintains a daily request counter in persistent storage. The beacon is written against Greasemonkey/Tampermonkey userscript APIs (GM_xmlhttpRequest, GM_getValue, GM_setValue, GM_info).

analyzed by
Leitwacht
first seen
Aug 31, 2026, 10:46 AM
analyzed
Aug 31, 2026, 10:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.