Hostile 93% javascript Download

log-taker 0.0.7

Exfiltrates sensitive data to remote server

Node reads shell history and sends it over HTTPRecursive file stealer targeting sensitive data
SHA-256e1e9ef03142315c4a56a1b95fe44a0f4a30413e5fcf0fe1800cea0c2144e741c

Also flagged by osv (MAL-2026-6338: Malicious code in log-taker (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.