cheerio-tool 1.0.5
Exfiltrates credentials and crypto wallets
Module-load posts harvested credentials to a direct-IP endpointReads developer credential stores and POSTs to a direct-IP HTTP endpoint
SHA-25623c728d435df4f9f50695a5e3d78e5a028feccdddece1464ddfa82b786514350
Also flagged by osv (MAL-2026-3756: Malicious code in cheerio-tool (npm)) +1 more.