LWA-2026-5748 MAL-2026-6338 ↗ confirmed malware

log-taker@0.0.7

Malicious code in log-taker (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

log-taker@0.0.7 is a credential and information stealer that scans the local filesystem for sensitive files and exfiltrates them to a remote C2. On execution, it enumerates home directories (Linux /home, macOS /Users) and all drives (Windows C:-J:) searching for .env files, Solana wallet files (id.json), config.toml, and documents containing wallet-related keywords (seed, mnemonic, privatekey, keystore, metamask, phantom). It collects shell history from bash, zsh, fish, and PowerShell. On Windows and macOS it also exfiltrates the Telegram Desktop tdata folder (session/auth keys), packed as a gzip archive. All stolen data is uploaded via multipart POST to hxxps://log-taker[.]store/api/v1, including the target's username and platform metadata.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 06:24 AM
analyzed
Jun 19, 2026, 06:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.