-= Per source details. Do not edit below this line.=-
Package is advertised as a lightweight TOTP/HOTP library, but its package.json declares a postinstall hook (node lib/core.js) that runs a Windows credential stealer on install. The payload enumerates Windows Credential Manager entries matching MCL|*|Xal* via inline P/Invoke PowerShell (CredEnumerate/CredRead), reads launcher account JSON files under %APPDATA%.minecraft\launcher_accounts*.json, extracts Microsoft Account refresh tokens (regex M.C...) and access tokens, and exchanges them at login.live.com/oauth20_token.srf, Xbox Live, and minecraftservices endpoints to obtain session identifiers. It also builds a Chromium DPAPI decryption chain (PowerShell [System.Security.Cryptography.ProtectedData]::Unprotect against os_crypt.encrypted_key from Chrome's Local State, plus an AES-256-GCM decipher) to decrypt browser cookie/credential blobs. Harvested data is posted as JSON and multipart file uploads to a hardcoded Discord webhook whose URL is concealed as an XOR-0x3F byte array (_W) decoded at runtime along with other sensitive strings (powershell, child_process, ProtectedData, discord user-agent). An _env() gate short-circuits on CI, during npm audit/npm pack, when %APPDATA%/USERPROFILE/USERNAME/COMPUTERNAME are missing, or when ~/Documents is absent, so the payload only fires on real Windows developer hosts. The 2FA description is a cover story.
1.0.1Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H