npm

common-tg-service

Telegram account-takeover framework disguised as a NestJS Telegram service utility. All 502 published versions (1.0.1 through 1.3.207) are malicious. Sets a hardcoded 2FA password on managed accounts, polls operator IMAP for the confirmation code, evicts other authorized devices, and forwards OTP login codes from chat 777000 to operator-controlled Telegram bot channels. Pulls runtime config from npoint.io with committed plaintext credentials.

discovered 2026-05-03

Threat types

credential_stealerdata_exfiltrationc2_agent

Malicious versions

  • 1.3.207 · 5061bc9611e31a48…
  • 1.0.1

Campaigns

Indicators

Techniques

Read the full analysis →