log-taker@0.0.7
Malicious code in log-taker (npm)
Analysis
log-taker@0.0.7 is a credential and information stealer that scans the local filesystem for sensitive files and exfiltrates them to a remote C2. On execution, it enumerates home directories (Linux /home, macOS /Users) and all drives (Windows C:-J:) searching for .env files, Solana wallet files (id.json), config.toml, and documents containing wallet-related keywords (seed, mnemonic, privatekey, keystore, metamask, phantom). It collects shell history from bash, zsh, fish, and PowerShell. On Windows and macOS it also exfiltrates the Telegram Desktop tdata folder (session/auth keys), packed as a gzip archive. All stolen data is uploaded via multipart POST to hxxps://log-taker[.]store/api/v1, including the target's username and platform metadata.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 06:24 AM
- analyzed
- Jun 19, 2026, 06:25 AM
Related advisories
- new-solt-1@0.0.9
- new-solt@0.0.7
- node-slot@1.0.7
- mjs-eslint-helper@4.0.1
- server-parket@3.8.1
- delta-time-32bb@1.0.0
- stream-read-35cf@1.0.0
- xboxauthwrapper@3.9.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.