LWA-2026-11818 MAL-2026-15813 ↗ confirmed malware

bt2-api-gateway-node-js@999.0.0

Malicious code in bt2-api-gateway-node-js (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

The postinstall hook runs index.js, which after a short delay harvests the installer's credentials and exfiltrates them. It reads ~/.npmrc, ~/.yarnrc, ~/.git-credentials, SSH private keys, AWS credentials and SSO cache, GCP application_default_credentials.json, Azure accessTokens.json, Anthropic/OpenAI/DeepSeek/HuggingFace/Replicate/Cohere/Gemini API keys, k8s config, docker config.json, terraform credentials, GitHub CLI hosts.yml, .netrc, Vercel/Netlify/Supabase/Firebase tokens, database password files, and every environment variable whose name contains TOKEN/KEY/SECRET/PASSWORD/API/AUTH/CREDENTIAL. The collected data is base64-encoded and POSTed to a Telegram bot (api[.]telegram[.]org, chat 8814152665) and to hxxp://2[.]26[.]82[.]63:8888/collect. The package exports only a stub API module and contains no real gateway functionality.

analyzed by
Leitwacht
first seen
Sep 1, 2026, 04:41 PM
analyzed
Sep 1, 2026, 04:42 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.