Logo
npm

secretkey2fa@1.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 2:33 PM UTC

Malicious

OSV ID

MAL-2026-15559

Ecosystem

npm

Summary

Package is advertised as a lightweight TOTP/HOTP library, but its package.json declares a postinstall hook (node lib/core.js) that runs a Windows credential stealer on install. The payload enumerates Windows Credential Manager entries matching MCL|*|Xal* via inline P/Invoke PowerShell (CredEnumerate/CredRead), reads launcher account JSON files under %APPDATA%\.minecraft\launcher_accounts*.json, extracts Microsoft Account refresh tokens (regex M.C...) and access tokens, and exchanges them at login.live.com/oauth20_token.srf, Xbox Live, and minecraftservices endpoints to obtain session identifiers. It also builds a Chromium DPAPI decryption chain (PowerShell [System.Security.Cryptography.ProtectedData]::Unprotect against os_crypt.encrypted_key from Chrome's Local State, plus an AES-256-GCM decipher) to decrypt browser cookie/credential blobs. Harvested data is posted as JSON and multipart file uploads to a hardcoded Discord webhook whose URL is concealed as an XOR-0x3F byte array (_W) decoded at runtime along with other sensitive strings (powershell, child_process, ProtectedData, discord user-agent). An _env() gate short-circuits on CI, during npm audit/npm pack, when %APPDATA%/USERPROFILE/USERNAME/COMPUTERNAME are missing, or when ~/Documents is absent, so the payload only fires on real Windows developer hosts. The 2FA description is a cover story.

Source: amazon-inspector (e1da4c2863f6f6fb95a1ab802243bfde5e04a71e4aa6f0b41f940502d58f501a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.