Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

2fa-secretkeynpm

2fa-secretkey is a confirmed malicious npm package (MAL-2026-15547) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.1, 1.0.2, 1.0.3…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in 2fa-secretkey (npm)

MAL-2026-15547
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall 2fa-secretkey

What this malware does

The package advertises itself as a TOTP/2FA helper but its package.json postinstall spawns lib/core.js as a detached, stdio-ignored child of the node runtime, so the payload runs automatically on npm install and outlives npm exit. lib/core.js hides its strings behind an XOR 0x3F char-code decoder that reconstructs a hardcoded discord.com/api/webhooks/... URL, a DPAPI class name, powershell.exe, AppData paths, and cmd tokens at runtime. Before running, _env() exits when CI, CONTINUOUS_INTEGRATION, JEST_WORKER_ID or npm_config_global are set, when APPDATA/USERPROFILE/USERNAME/COMPUTERNAME are missing, when the lifecycle script name contains 'audit' or 'pack', or when %USERPROFILE%/Documents is absent, gating execution to real Windows user machines. On Windows the payload shells out to powershell.exe with an inline C# Add-Type that P/Invokes advapi32 CredEnumerate/CredRead to dump 'MCL||Xal.' entries from Windows Credential Manager, extracts Microsoft refresh tokens and JWT access tokens, and trades them via login.live.com, XBL, XSTS and api.minecraftservices.com to mint Minecraft session IDs. It additionally reads the Chromium Local State encrypted_key, strips the DPAPI prefix, calls System.Security.Cryptography.ProtectedData::Unprotect through PowerShell to recover the browser master key, and AES-256-GCM-decrypts cookies and stored credentials. The collected material is POSTed as JSON and multipart uploads (tagged with the OS username and '@everyone') to the XOR-decoded Discord webhook endpoint, which is unrelated to the package's advertised TOTP purpose and is not caller-configurable.

Malicious versions

7 flagged
1.0.11.0.21.0.31.0.41.0.51.0.61.0.7

Indicators of compromise (SHA-256)

1afe6a146679af33f711ab93de8e6b71acb6377b50a5fcff765130d9ca13c34c
c57ce2e0a40135d182f0ee06ff17c7bd8bfdaff1a3a3160d4c1358d6dfd16249
d6fb9a8b0d5d1f044f585f6e8316d845141eef3fd7556e4264918975a2a9df2d
d81366920353e4098b6c52b8d3ff03bd47b29479b94e53e52ae8e29919e4417d
2da42e350014b4d2f6bc3b5f1fc86d31bcefb0106d8a8af8b466c3221c757f72
8458c66987512aafeb111d45ec4c5639bc5bb43cd342777b9972e727719fe2b7
b7a00fd5e8a87938baf406799f7b110eb81f9f70b113a69de5dfdd706723d99e

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for 2fa-secretkey (7 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging 2fa-secretkey across your stack and pipelines.

  2. If you installed it — respond

    2fa-secretkey is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If 2fa-secretkey was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks 2fa-secretkey before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. 2fa-secretkey on npm has been identified as a malicious package (versions 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-019122IN-MAL-2026-019120IN-MAL-2026-019117IN-MAL-2026-019118IN-MAL-2026-019121IN-MAL-2026-019119IN-MAL-2026-019123

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks 2fa-secretkey-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore