llama-tokenizer@1.2.2
Malicious code in llama-tokenizer (npm)
Analysis
llama-tokenizer@1.2.2 is a trojanized clone of the legitimate llama-tokenizer-js package. On require(), it downloads a binary from hxxps://filament-zap[.]vercel[.]app/service/assets/fetchBinary (Windows) or hxxps://filament-zap[.]vercel[.]app/service/assets/fetchLinuxBinary (Linux), saves it to ~/.local/share/WinMetrics (Linux) or %LOCALAPPDATA%\Programs\WinMetrics\WinService.exe (Windows), and spawns it as a detached background process that outlives the parent. The package has no repository and its README is a verbatim copy of the real llama-tokenizer-js documentation.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 06:57 PM
- analyzed
- Jul 10, 2026, 06:58 PM
Related advisories
- eth-react-redirection@1.0.0
- ohcm-culture-formatting@5.0.0
- theta-sdk-js@1.2.14
- chunk-parser@1.0.0
- nonenull1@1.0.0
- type-slint@3.3.7
- chai-as-smart@2.3.5
- @wagni_bot/pumpfun-sdk@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.