← All analysed packages

npm package

totp-utils
version 1.4.3 · detonated 2026-08-21 · isolated sandbox
⚠ Flagged as suspicious
Full analysis totp-utils 1.4.2–1.4.4 — Discord and Minecraft credential theft with a second-stage browser stealer
What it did
  • Resolved 2 domain(s) during install.
    discord.comregistry.npmjs.org
  • Read 2 sensitive path(s).
    /home/det/.npmrc/tmp/detonate.lXKFyw/.npmrc

Protet continuously detonates newly-published npm packages in an isolated sandbox and scores what they actually do at install and run time. totp-utils 1.4.3 was flagged as suspicious on the strength of the behaviour above — its observed behaviour is consistent with malicious activity. This is automated analysis of public packages and may include false positives; it is not a definitive determination. Browse every package we've flagged.