LWA-2026-6606 MAL-2026-10163 ↗ confirmed malware

llama-tokenizer@1.2.2

Malicious code in llama-tokenizer (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

llama-tokenizer@1.2.2 is a trojanized clone of the legitimate llama-tokenizer-js package. On require(), it downloads a binary from hxxps://filament-zap[.]vercel[.]app/service/assets/fetchBinary (Windows) or hxxps://filament-zap[.]vercel[.]app/service/assets/fetchLinuxBinary (Linux), saves it to ~/.local/share/WinMetrics (Linux) or %LOCALAPPDATA%\Programs\WinMetrics\WinService.exe (Windows), and spawns it as a detached background process that outlives the parent. The package has no repository and its README is a verbatim copy of the real llama-tokenizer-js documentation.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 06:57 PM
analyzed
Jul 10, 2026, 06:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.