tg-msg-effect@1.0.10
Malicious code in tg-msg-effect (npm)
Analysis
This package impersonates a Telegram message-effect library but is a credential stealer. On import it spawns a detached background process that scans all drives (C: through Z:) for Telegram Desktop session data ('tdata' directory) and cryptocurrency wallet key directories ('key_datas'). Inside those directories it collects files with 16-character hex names (private keys) and packages everything into a zip archive. The archive is exfiltrated to a Telegram bot via POST to api[.]telegram[.]org/bot.../sendDocument with a hardcoded chat ID. This steals the victim's Telegram login session and crypto wallet keys.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 02:17 AM
- analyzed
- Jun 15, 2026, 02:20 AM
Related advisories
- testzapier@1.0.0
- stylelint-standard@1.2.0
- sjs-builders@1.0.4
- sisubeny-bun-pwn-payload-1@1.0.0
- sickle-wrapper@0.2.0
- pretty-pino-logger@2.0.2
- pretty-fancy@1.0.1
- prettlog@1.0.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.