LWA-2026-10794 MAL-2026-13617 ↗ confirmed malware

ts-utility-plus@1.3.2

Malicious code in ts-utility-plus (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

ts-utility-plus@1.3.2 is a remote-code-execution dropper. Its main entry point (index.js) fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/109 (HTTP header bearrtoken:logo) and executes the response body via the Function constructor with a full Node.js context exposed (require, process, Buffer, global, setTimeout), so the remotely-served code runs with full access to the host. The package is described as a TypeScript utility toolkit but contains no utilities — the entire module is a fetch-and-exec dropper with a retry loop. The C2-served stage is not shipped in the tarball, so its behaviour is determined by the remote server.

analyzed by
Leitwacht
first seen
Aug 7, 2026, 04:56 PM
analyzed
Aug 7, 2026, 04:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.