secret-key-totpnpm
Advisory published Updated
secret-key-totp is a confirmed malicious npm package (MAL-2026-14439) that steals credentials and exfiltrates sensitive data (malicious version 1.5.1). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in secret-key-totp (npm)
What this malware does
[email protected] declares a postinstall hook (node./index.js --setup) that executes a credential stealer and dropper on install, and the same routine also fires when the library API (e.g. validateSecret) is called. The stealer walks Minecraft launcher account stores (vanilla launcher_accounts*.json, Lunar, Essential, CurseForge, Modrinth) and Discord/Chromium browser Local Storage (Discord, Chrome, Edge, Brave, Opera leveldb), decrypting Windows DPAPI+AES-GCM protected material, then POSTs the harvested tokens to a hardcoded Discord webhook whose URL is assembled from split string fragments (["https://dis","cord.com/api/","webhooks/153242923376",...].join("")). A second stage fetches an unpinned binary from a Discord CDN attachment URL (also string-split obfuscated) and writes it as optimized-renderer-1.0.0.jar into every discovered Minecraft mods folder (vanilla .minecraft/mods, Modrinth profile mods dirs, Lunar offline versions), providing persistence and further code execution inside the Minecraft process on next launch. Sandbox/CI evasion (_isSandbox checks CI, npm_config_global, JEST_WORKER_ID, npm_lifecycle_script containing audit/pack, and missing USERPROFILE/APPDATA/Documents) plus a 3-6 second randomized delay are used to make npm install appear clean.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Credential / info stealerFind it
Search your lockfiles and build artifacts for secret-key-totp (version 1.5.1).
If you installed it — respond
secret-key-totp is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.
Did it already run?
If secret-key-totp was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks secret-key-totp-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.