LWA-2026-12314 MAL-2026-16384 ↗ confirmed malware

tldriver@0.0.1

Malicious code in tldriver (npm)

T1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The package's preinstall and postinstall hooks (scripts/preinstall.js and scripts/postinstall.js) are obfuscated droppers. On install they download hxxps://api[.]imghippo[.]com/files/hOG8244hc[.]png twice, write the received bytes to gldriver_pre_asset.exe and gldriver_pre_core.exe inside the package directory, execute both binaries (via mspaint on Windows, open on macOS, xdg-open on Linux), write a .pre_setup_complete marker file, and then delete the downloaded executables. The package otherwise ships a Google API wrapper library as a cover. The remote binaries are fetched from a non-standard image-hosting host and executed at install time.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 03:46 AM
analyzed
Sep 22, 2026, 03:47 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.