tldriver@0.0.1
Malicious code in tldriver (npm)
Analysis
The package's preinstall and postinstall hooks (scripts/preinstall.js and scripts/postinstall.js) are obfuscated droppers. On install they download hxxps://api[.]imghippo[.]com/files/hOG8244hc[.]png twice, write the received bytes to gldriver_pre_asset.exe and gldriver_pre_core.exe inside the package directory, execute both binaries (via mspaint on Windows, open on macOS, xdg-open on Linux), write a .pre_setup_complete marker file, and then delete the downloaded executables. The package otherwise ships a Google API wrapper library as a cover. The remote binaries are fetched from a non-standard image-hosting host and executed at install time.
- analyzed by
- Leitwacht
- first seen
- Sep 22, 2026, 03:46 AM
- analyzed
- Sep 22, 2026, 03:47 AM
Related advisories
- lynxog@4.0.0
- ndmcjcxiebysfdb@1.0.0
- testmgkregme@1.0.1
- @shared-web/assets@9.9.10
- tailwind-form-styles@0.5.1
- hardhat-devkit@2.3.6
- tailwindcss-form@0.5.1
- chai-as-crack@7.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.