textdecode@1.2.7
Malicious code in textdecode (npm)
Analysis
textdecode@1.2.7 is a credential-stealing Trojan disguised as a text decoder library. When required, lib/utf8-decoder.js (heavily obfuscated) executes immediately. It decrypts browser-saved credentials from Chrome, Edge, and Brave using the Windows DPAPI (via @primno/dpapi), reads stored passwords and cookies from browser profile directories (Login Data, Cookies, Local State). It targets 30+ crypto wallet browser extensions including Metamask, Coinbase, Phantom, Trust, BinanceChain, Exodus, Keplr, OKX, and others by scanning their extension storage. It steals Discord authentication tokens from both the Discord desktop app (Local Storage, leveldb) and browser profiles. It collects system fingerprints (hostname, username, OS, architecture, hardware UUID via wmic). Stolen data is exfiltrated through the Dropbox API (api[.]dropboxapi[.]com and content[.]dropboxapi[.]com) using hardcoded application credentials for uploading/downloading files. It uses PowerShell with hidden windows to zip collected data, and can kill processes via taskkill.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 10:47 PM
- analyzed
- Jun 14, 2026, 10:48 PM
Related advisories
- ne-logger@0.5.0
- web3-core-utils@4.3.5
- simple-date-formatter-new-5@1.0.0
- simple-date-formatter-util-5@1.0.0
- mcp-dev-toolkit@1.5.0
- @across-toolkit/eslint-config@99.0.1
- antsrcsrctest@1.0.0
- hello244b@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.