LWA-2026-6820 MAL-2026-10750 ↗ confirmed malware

telemetry-metrics@0.2.1

Malicious code in telemetry-metrics (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool TransferT1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

telemetry-metrics@0.2.1 is a trojanized clone of the legitimate @telemetry-js/telemetry metrics library. The README is copied verbatim from the real project, but the code has been modified: when the module is loaded, it fetches a remote payload from hxxps://raw[.]githubusercontent[.]com/ThoSuperstarDev/axios-http/main/lib/env/te[.]txt and writes it to C:\Windows\1.txt on the filesystem. The package has no repository and no tests, and its only declared dependency (combine-errors) is a decoy from the original project.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 06:09 PM
analyzed
Jul 15, 2026, 06:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.