etoro-aggregator@999.0.0
Malicious code in etoro-aggregator (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
etoro-aggregator@999.0.0 is a dependency-confusion stub that impersonates an eToro API client. Its preinstall hook runs node preinstall.js, which sends an HTTP GET to hxxp://209[.]126[.]81[.]147/etoro-depconf-poce346552f776f/npm/{hostname}/{username}/{cwd}, exfiltrating the installer's hostname, username, and working directory to the remote IP 209[.]126[.]81[.]147. The hook swallows errors (|| true) so the beacon runs silently during install.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 04:02 AM
- analyzed
- Sep 10, 2026, 04:04 AM
Related advisories
- etoro-cashout@999.0.0
- etoro-builders@999.0.0
- etoro-billing@999.0.0
- etoro-api@999.0.0
- etoro-core@999.0.0
- etoro-client@999.0.0
- etoro-charts@999.0.0
- memfd-secret@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.