tailmagic@2.3.2
Malicious code in tailmagic (npm)
Analysis
tailmagic@2.3.2 is a malicious npm package that, when required, fetches a second-stage payload from bet[.]slotgambit[.]com/icons/106 (with custom header bearrtoken: "logo") and executes it server-side via new Function() with full Node.js API access (require, process, Buffer, console, setTimeout, Promise). The advertised API (setDefault) does not exist; the module's real export runs the loader immediately on require. The payload's dependencies suggest second-stage capabilities including browser credential theft (via @primno/dpapi to decrypt Windows DPAPI data, sqlite3/better-sqlite3 for Chrome cookie databases, node-machine-id for host fingerprinting, and socket[.]io-client for real-time C2).
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 01:47 PM
- analyzed
- Jun 14, 2026, 01:49 PM
Related advisories
- tabbables@45.0.0
- system-driver@1.0.1
- sycm-vendors@55.0.0
- swplayer-react-sl@1.0.5
- super-useful-omega-package-123@0.2.1
- strutil-kit@1.0.0
- streamvault@1.0.1
- st-pathhelper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.