LWA-2026-11351 confirmed malware
tyepescript-cli@1.0.0
Malicious code in tyepescript-cli (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (scripts/postinstall.js) fingerprints the host (platform, arch, node version, WSL detection via /proc/version) and POSTs the platform to C2 193[.]70[.]34[.]101:20099/vote. On Windows or WSL hosts it then downloads a second-stage binary main.exe from a GitHub release URL (hxxps://github[.]com/be[.][.][.]/releases/download/null/main[.]exe) and executes it detached with stdio ignored and windowsHide, or via an exec bridge on WSL. The package is a typosquat of typescript-cli.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:52 AM
- analyzed
- Aug 16, 2026, 02:57 AM
Related advisories
- lodahsjs@1.0.0
- lodahs-cli@1.0.0
- commandor-core@1.0.0
- lodhash-cli@1.0.0
- chalk-core@1.0.0
- comander-cli@1.0.0
- sysdo@1.0.0
- harmony-app-toolkit@21.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.