← All analysed packages
npm package
totp-utils
version 1.4.3 · detonated 2026-08-21 · isolated sandbox
⚠ Flagged as suspicious
Full analysis
totp-utils 1.4.2–1.4.4 — Discord and Minecraft credential theft with a second-stage browser stealer
What it did
- Resolved 2 domain(s) during install.
discord.comregistry.npmjs.org - Read 2 sensitive path(s).
/home/det/.npmrc/tmp/detonate.lXKFyw/.npmrc
Protet continuously detonates newly-published npm packages in an isolated sandbox and scores what they actually do at install and run time. totp-utils 1.4.3 was flagged as suspicious on the strength of the behaviour above — its observed behaviour is consistent with malicious activity. This is automated analysis of public packages and may include false positives; it is not a definitive determination. Browse every package we've flagged.