msc-terminal@3.2.0
Malicious code in msc-terminal (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
The package's install hook executes a bundled script that re-spawns itself as a detached, output-suppressed process for persistence and evasion. It ships an 836KB heavily obfuscated payload (dictionary-array obfuscation, base64 decoding via atob) that uses child_process and fetch for command execution and network exfiltration.
- analyzed by
- Leitwacht
- first seen
- May 26, 2026, 05:22 PM
- analyzed
- May 26, 2026, 07:19 PM
Related advisories
- @asavie/i18n@99.0.3
- forge-jsxy@1.0.91
- eslint-plugin-vitest-ts@1.0.4
- fundraiserserv@28.0.0
- relativity-pdfjs-dist@99.9.9
- client-cookies-agent@99.9.7
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.