VYPR

npm · Malicious package advisory

Malware

@telekom-wfa/auth-core

MAL-2026-2523

Malicious code in @telekom-wfa/auth-core (npm)

Details

Package is malware. Hardcoded Telegram credentials, data exfiltration, and preinstall script execution indicate malicious intent.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9a2fe12e5542ae8cf1cf339c13c3480629ccfd6e2fb391427c4f1b17bbdc9f85)
The package @telekom-wfa/auth-core was found to contain malicious code.

Compromised versions (1)

  • 99.9.11

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.