etoro-client@999.0.0
Malicious code in etoro-client (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
etoro-client@999.0.0 is a dependency-confusion stub impersonating an eToro API client. Its preinstall hook runs preinstall.js, which sends an HTTP GET to hxxp://209[.]126[.]81[.]147/etoro-depconf-poce346552f776f/npm/{hostname}/{username}/{cwd}, exfiltrating the installer's hostname, OS username, and working directory to a remote IP at install time. The package contains no real client code.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 04:02 AM
- analyzed
- Sep 10, 2026, 04:03 AM
Related advisories
- soltinel-pro@0.2.2
- gmgn-trading-kit@1.7.0
- @davidov0516/string-utils@1.1.3
- @umschool/platform@999.0.0
- polygon-toolkits-validator@1.1.4
- krdpass-auth-react-native@10.0.0
- alloy-graphql@1.0.1
- date-fns-formatter@1.3.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.