ts-utility-plus@1.3.2
Malicious code in ts-utility-plus (npm)
Analysis
ts-utility-plus@1.3.2 is a remote-code-execution dropper. Its main entry point (index.js) fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/109 (HTTP header bearrtoken:logo) and executes the response body via the Function constructor with a full Node.js context exposed (require, process, Buffer, global, setTimeout), so the remotely-served code runs with full access to the host. The package is described as a TypeScript utility toolkit but contains no utilities — the entire module is a fetch-and-exec dropper with a retry loop. The C2-served stage is not shipped in the tarball, so its behaviour is determined by the remote server.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 04:56 PM
- analyzed
- Aug 7, 2026, 04:56 PM
Related advisories
- forge-gas-diff@1.0.0
- damir-cbr-dawdntrnssbf@35.8.1
- platform-ui-colors@35.8.1
- distributorblock@35.8.1
- dolyame-ui-attachfile@35.8.1
- dolyame-ui-buttonstore@35.8.1
- dolyame-ui-clickoutsidehoc@35.8.1
- dolyame-ui-cardlogo@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.