telemetry-metrics@0.2.1
Malicious code in telemetry-metrics (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool TransferT1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
telemetry-metrics@0.2.1 is a trojanized clone of the legitimate @telemetry-js/telemetry metrics library. The README is copied verbatim from the real project, but the code has been modified: when the module is loaded, it fetches a remote payload from hxxps://raw[.]githubusercontent[.]com/ThoSuperstarDev/axios-http/main/lib/env/te[.]txt and writes it to C:\Windows\1.txt on the filesystem. The package has no repository and no tests, and its only declared dependency (combine-errors) is a decoy from the original project.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 06:09 PM
- analyzed
- Jul 15, 2026, 06:10 PM
Related advisories
- metrics-ui@99.9.1
- react-hook-scripts@5.4.2
- code-formatter-setup@1.0.0
- ai-pro-sdk@2.0.3
- react-hook-doms@5.3.1
- assertion-utils-js@2.4.3
- @risaoffc/baileys@8.0.3
- chai-as-hardened@7.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.