etoro-charts@999.0.0
Malicious code in etoro-charts (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
The package impersonates the eToro charting library (name "etoro-charts", version 999.0.0) and runs a preinstall hook on install that silently sends an HTTP request to hxxp://209[.]126[.]81[.]147/etoro-depconf-poce346552f776f/npm/{hostname}/{username}/{cwd}, exfiltrating the installer's hostname, username, and working directory to a remote IP. The hook swallows errors with `|| true` so the beacon runs without alerting the installer.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 04:02 AM
- analyzed
- Sep 10, 2026, 04:03 AM
Related advisories
- etoro-charts@99.0.0 same package
- memfd-secret@1.0.0
- @umschool/platform@999.0.0
- krdpass-auth-react-native@10.0.0
- alloy-graphql@1.0.1
- feishu-docx-mcp@0.3.2
- bmc-i18n-extract-cli@1.1.1
- bmc-translate-utils@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.