Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

secret-key-totpnpm

Advisory published Updated

secret-key-totp is a confirmed malicious npm package (MAL-2026-14439) that steals credentials and exfiltrates sensitive data (malicious version 1.5.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in secret-key-totp (npm)

MAL-2026-14439
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall secret-key-totp

What this malware does

[email protected] declares a postinstall hook (node./index.js --setup) that executes a credential stealer and dropper on install, and the same routine also fires when the library API (e.g. validateSecret) is called. The stealer walks Minecraft launcher account stores (vanilla launcher_accounts*.json, Lunar, Essential, CurseForge, Modrinth) and Discord/Chromium browser Local Storage (Discord, Chrome, Edge, Brave, Opera leveldb), decrypting Windows DPAPI+AES-GCM protected material, then POSTs the harvested tokens to a hardcoded Discord webhook whose URL is assembled from split string fragments (["https://dis","cord.com/api/","webhooks/153242923376",...].join("")). A second stage fetches an unpinned binary from a Discord CDN attachment URL (also string-split obfuscated) and writes it as optimized-renderer-1.0.0.jar into every discovered Minecraft mods folder (vanilla .minecraft/mods, Modrinth profile mods dirs, Lunar offline versions), providing persistence and further code execution inside the Minecraft process on next launch. Sandbox/CI evasion (_isSandbox checks CI, npm_config_global, JEST_WORKER_ID, npm_lifecycle_script containing audit/pack, and missing USERPROFILE/APPDATA/Documents) plus a 3-6 second randomized delay are used to make npm install appear clean.

Malicious versions

1 flagged
1.5.1

Indicators of compromise (SHA-256)

0f662164281fe877686c7eac93e0e6d068ccb16f8bff1b44029b1ace655a76b6

Detection & response playbook

Credential / info stealer
  1. Find it

    Search your lockfiles and build artifacts for secret-key-totp (version 1.5.1).

  2. If you installed it — respond

    secret-key-totp is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If secret-key-totp was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. secret-key-totp on npm has been identified as a malicious package (version 1.5.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-018636

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks secret-key-totp-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

secret-key-totp (npm) malicious package — MAL-2026-14439 | O3 Security