LWA-2026-5246 confirmed malware

tailmagic@2.3.2

Malicious code in tailmagic (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

tailmagic@2.3.2 is a malicious npm package that, when required, fetches a second-stage payload from bet[.]slotgambit[.]com/icons/106 (with custom header bearrtoken: "logo") and executes it server-side via new Function() with full Node.js API access (require, process, Buffer, console, setTimeout, Promise). The advertised API (setDefault) does not exist; the module's real export runs the loader immediately on require. The payload's dependencies suggest second-stage capabilities including browser credential theft (via @primno/dpapi to decrypt Windows DPAPI data, sqlite3/better-sqlite3 for Chrome cookie databases, node-machine-id for host fingerprinting, and socket[.]io-client for real-time C2).

analyzed by
Leitwacht
first seen
Jun 14, 2026, 01:47 PM
analyzed
Jun 14, 2026, 01:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.