LWA-2026-7059 confirmed malware

@tobyvalk123/tixte@1.0.2

Malicious code in @tobyvalk123/tixte (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The postinstall hook (scripts/postinstall.js) collects the installer's full environment variables (process.env), system username, and hostname, base64-encodes the data, and exfiltrates it via an HTTPS GET request to gjsidn[.]co/collect. The environment variables commonly contain NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, and other credentials, making this a credential-theft payload delivered through a trojanized string-utility package.

analyzed by
Leitwacht
first seen
Jul 23, 2026, 12:40 PM
analyzed
Jul 23, 2026, 12:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.