LWA-2026-11976 MAL-2026-16113 ↗ confirmed malware

etoro-api@999.0.0

Malicious code in etoro-api (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

Dependency-confusion stub impersonating the eToro API client (sentinel version 999.0.0, no real API code — index.js is an empty module). Its preinstall hook runs preinstall.js, which collects the installer's hostname, username, and working directory and sends them via HTTP GET to hxxp://209[.]126[.]81[.]147/etoro-depconf-poce346552f776f/npm/<hostname>/<username>/<cwd>. The hook swallows errors (|| true) so the beacon runs silently during install.

analyzed by
Leitwacht
first seen
Sep 10, 2026, 04:02 AM
analyzed
Sep 10, 2026, 04:03 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.