LWA-2026-5278 confirmed malware

textdecode@1.2.7

Malicious code in textdecode (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1082 · System Information DiscoveryT1555.003 · Credentials from Web BrowsersT1552.001 · Credentials In FilesT1539 · Steal Web Session CookieT1525 · Implant Internal ImageT1567.001 · Exfiltration to Code RepositoryT1071.001 · Web Protocols

Analysis

textdecode@1.2.7 is a credential-stealing Trojan disguised as a text decoder library. When required, lib/utf8-decoder.js (heavily obfuscated) executes immediately. It decrypts browser-saved credentials from Chrome, Edge, and Brave using the Windows DPAPI (via @primno/dpapi), reads stored passwords and cookies from browser profile directories (Login Data, Cookies, Local State). It targets 30+ crypto wallet browser extensions including Metamask, Coinbase, Phantom, Trust, BinanceChain, Exodus, Keplr, OKX, and others by scanning their extension storage. It steals Discord authentication tokens from both the Discord desktop app (Local Storage, leveldb) and browser profiles. It collects system fingerprints (hostname, username, OS, architecture, hardware UUID via wmic). Stolen data is exfiltrated through the Dropbox API (api[.]dropboxapi[.]com and content[.]dropboxapi[.]com) using hardcoded application credentials for uploading/downloading files. It uses PowerShell with hidden windows to zip collected data, and can kill processes via taskkill.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 10:47 PM
analyzed
Jun 14, 2026, 10:48 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.