tol8t@14.0.0
Malicious code in tol8t (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1567 · Exfiltration Over Web Service
Analysis
The package contains no code — only a package.json whose preinstall and postinstall hooks run wget to POST host metadata to an attacker-controlled Discord webhook (discord[.]com/api/webhooks/1413937656697720862/rU1d2bB96KG-VrhF5qfz2Pes-Mz3cvvxYgpntwTZajFl0NomlaISU3s7TDGHsqWjltxf). On install it exfiltrates the current working directory ($(pwd)) and the machine hostname to that webhook, beaconing every install to the attacker's Discord channel.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 08:00 PM
- analyzed
- Sep 15, 2026, 08:02 PM
Related advisories
- tetotest@14.0.0
- @firelordzuka/pulse-poc@1.0.0
- discord-resolvers@3.4.2
- @consts/links@9.9.9
- discord-players@3.4.2
- kamafhbnowct@1.0.0
- soltinel-pro@0.2.2
- @davidov0516/string-utils@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.