chalk-es@1.0.0
Malicious code in chalk-es (npm)
Analysis
chalk-es@1.0.0 (a combosquat of the chalk package) runs a malicious postinstall hook (scripts/postinstall.js) on install. The hook fingerprints the host (platform, WSL detection), POSTs a platform beacon to C2 193[.]70[.]34[.]101:20099 at path /vote, then on Windows/WSL systems downloads a native binary from hxxps://github[.]com/bezbz1/qzM50VKAG0rVlH/releases/download/main[.]exe to %TEMP%\main.exe and executes it as a detached process. On WSL it instead runs an XOR-decoded bridge-launcher command via exec. Payload URLs and C2 addresses are XOR-obfuscated in the script.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:48 AM
- analyzed
- Aug 16, 2026, 02:49 AM
Related advisories
- chalk-lib@1.0.0
- mutex-thread@1.3.0
- @hzero-front-ui/core@99.99.99
- datetime-fmt-xutil@1.0.0
- check-audit@99.9.1
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
- dakumangalsingh@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.