data-parser-utils@3.0.2
Malicious code in data-parser-utils (npm)
Analysis
data-parser-utils@3.0.2 is a trojanized package that fraudulently presents itself as a decimal arithmetic library but contains a credential and data theft payload executed via postinstall hook (node test.js). On npm install, the package scans the victim's filesystem for sensitive files: .env files, cryptocurrency wallet keystores (phantom, metamask, mnemonic, privatekey, seed, trezor, ledger), and documents containing wallet/crypto keywords across home directories and all drive letters (Linux /home/*, Windows C:-J:\, macOS /Users/*). It harvests bash, zsh, fish, and PowerShell shell histories. On Windows and macOS, it locates and archives the Telegram Desktop "tdata" session directory, containing authentication credentials. All stolen data is exfiltrated via multipart POST to hxxps://vercel-backend-green-five[.]vercel[.]app/api/v1. The package also ships a .npmrc file containing a live npm authentication token harvested from a prior victim.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 01:28 PM
- analyzed
- Jun 25, 2026, 01:29 PM
Related advisories
- ref-slot@1.0.9
- block-slot@1.0.9
- pino-zod@1.0.121
- zod-pino@1.0.122
- hyperpure-core@1.0.0
- zomato-config@1.0.0
- @npmresearch3/metrics-probe-dfda@1.0.0
- local-ip-helper@0.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.