Hostile 100% javascript Download

cheerio-tool 1.0.5

Exfiltrates credentials and crypto wallets

Module-load posts harvested credentials to a direct-IP endpointReads developer credential stores and POSTs to a direct-IP HTTP endpoint

Also flagged by osv (MAL-2026-3756: Malicious code in cheerio-tool (npm)) +1 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.