Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

totp-utilsnpm

Advisory published Updated

totp-utils is a confirmed malicious npm package (MAL-2026-14379) that steals credentials and exfiltrates sensitive data (malicious versions 1.4.2, 1.4.3, 1.4.4…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in totp-utils (npm)

MAL-2026-14379
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall totp-utils

What this malware does

Package advertises itself as a TOTP utility but its postinstall script (node./index.js --setup 2>/dev/null || true) and its exported validateSecret API both invoke a hidden _run() routine that (1) scans Discord/Chrome/Edge/Brave/Opera LevelDB stores under os.homedir() for Discord auth-token regexes, DPAPI-decrypts encrypted tokens via a spawned powershell ProtectedData.Unprotect call, parses Minecraft launcher credentials (vanilla launcher_accounts.json, Lunar accounts.json, ModrinthApp app.db JWTs), validates the harvested Discord tokens against discord.com/api/v9, and POSTs the collected credentials to a hardcoded Discord webhook whose URL is stored as chunked base64 in _x and reassembled at runtime (Buffer.from(_x.join(''),'base64')) to a discord.com/api/webhooks/1532429233769419004/... endpoint; and (2) enumerates vanilla/Modrinth/Lunar Minecraft profile mods/ directories and writes an opaque JAR named optimized-renderer-1.0.0.jar (URL also stored as chunked base64 decoding to cdn.discordapp.com/attachments/1507484731535785994/1540335670831222894/optimized-renderer-1.0.0.jar) into each discovered mods folder, delivering unverified code that will execute the next time the user launches Minecraft with a Fabric loader. The postinstall suppresses stderr and uses a 4-second setTimeout to appear to finish cleanly. Because validateSecret (part of the three-function public API) schedules _run() via setImmediate, the same theft and dropper also fire whenever a downstream consumer imports the package and calls the advertised TOTP function — extending the attack surface well beyond install time.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'totp-utils' @ 1.4.4 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Malicious versions

8 flagged
1.4.21.4.31.4.41.4.51.4.61.4.71.4.81.4.9

Indicators of compromise (SHA-256)

159988f0acc3ba380dd82b99d2cce2a3970e07aa7494c39c549f0ba88b7d787a
46699d4670a172968db679dd8d8061283ccfbf9eee4554c6a6ce0e67eb16d6e3
5734460fd684f09f39708d3033d94ce9c8e583c83894b949bd4a47520004922d
887df98d985be698c6ed663d1ca5704d80b2d60786836d75994cf0eb4a974127
8cebaa0a3370c12104ef2816420193171f431df0d113fdc5d8c9f1dc921deeb5
b47329f2fed5aec352ee8075511b4c376383589353751c6af797d5f683707298
ece76e4c56511dbf378c70d9a4e9ea57114f2e11d1d9a257cb54e44a0973012e
f6231fb9eaa1f92b21582e78502121021602c785ab96a4d19086cc0c4967d254
145fefb1ae148805aea6871e4815b86fb21f89d31230787f8a9a5eb8e5a1cea2
9c45116c29a00a054ccdbbef39b740b4551b671bdb999a0c8d76deac16b9352e
540564c8df54a933b6fb7f053cc98136e52caa53f6eb74a96fa0d1597ba4479a

Detection & response playbook

Credential / info stealer
  1. Find it

    Search your lockfiles and build artifacts for totp-utils (8 malicious versions).

  2. If you installed it — respond

    totp-utils is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If totp-utils was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. totp-utils on npm has been identified as a malicious package (versions 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-018557IN-MAL-2026-018554IN-MAL-2026-018555IN-MAL-2026-018553IN-MAL-2026-018556IN-MAL-2026-018558IN-MAL-2026-018550IN-MAL-2026-018552GHSA-m72r-95xc-q6g8

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks totp-utils-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

totp-utils (npm) malicious package — MAL-2026-14379 | O3 Security