LWA-2026-7059 confirmed malware
@tobyvalk123/tixte@1.0.2
Malicious code in @tobyvalk123/tixte (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The postinstall hook (scripts/postinstall.js) collects the installer's full environment variables (process.env), system username, and hostname, base64-encodes the data, and exfiltrates it via an HTTPS GET request to gjsidn[.]co/collect. The environment variables commonly contain NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, and other credentials, making this a credential-theft payload delivered through a trojanized string-utility package.
- analyzed by
- Leitwacht
- first seen
- Jul 23, 2026, 12:40 PM
- analyzed
- Jul 23, 2026, 12:41 PM
Related advisories
- vectormark@1.0.0
- xerohub-discord-voice-v2@1.8.0
- code-analyzer-mcp@1.0.0
- habingeer@2.1.6
- og-boost-br@1.0.0
- crypto-javas@2.0.8
- n8n-nodes-net-utils@1.0.0
- n8n-nodes-utils-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.