LWA-2026-5281 confirmed malware

tg-msg-effect@1.0.10

Malicious code in tg-msg-effect (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

This package impersonates a Telegram message-effect library but is a credential stealer. On import it spawns a detached background process that scans all drives (C: through Z:) for Telegram Desktop session data ('tdata' directory) and cryptocurrency wallet key directories ('key_datas'). Inside those directories it collects files with 16-character hex names (private keys) and packages everything into a zip archive. The archive is exfiltrated to a Telegram bot via POST to api[.]telegram[.]org/bot.../sendDocument with a hardcoded chat ID. This steals the victim's Telegram login session and crypto wallet keys.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 02:17 AM
analyzed
Jun 15, 2026, 02:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.