LWA-2026-5973 MAL-2026-6490 ↗ confirmed malware

data-parser-utils@3.0.2

Malicious code in data-parser-utils (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1555.007 · Steal Application Access Token

Analysis

data-parser-utils@3.0.2 is a trojanized package that fraudulently presents itself as a decimal arithmetic library but contains a credential and data theft payload executed via postinstall hook (node test.js). On npm install, the package scans the victim's filesystem for sensitive files: .env files, cryptocurrency wallet keystores (phantom, metamask, mnemonic, privatekey, seed, trezor, ledger), and documents containing wallet/crypto keywords across home directories and all drive letters (Linux /home/*, Windows C:-J:\, macOS /Users/*). It harvests bash, zsh, fish, and PowerShell shell histories. On Windows and macOS, it locates and archives the Telegram Desktop "tdata" session directory, containing authentication credentials. All stolen data is exfiltrated via multipart POST to hxxps://vercel-backend-green-five[.]vercel[.]app/api/v1. The package also ships a .npmrc file containing a live npm authentication token harvested from a prior victim.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 01:28 PM
analyzed
Jun 25, 2026, 01:29 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.