LWA-2026-11352 confirmed malware
typescipt-cli@1.0.0
Malicious code in typescipt-cli (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (scripts/postinstall.js) of this package, a typosquat of typescript-cli, XOR-decodes a hardcoded C2 endpoint and a remote binary URL. On install it POSTs host platform information to 193[.]70[.]34[.]101:20099/vote. On Windows and WSL hosts it downloads a binary (main.exe) from github[.]com/beebraz1/qPzM50V1AKG0rVlH/release/download/null/main.exe and executes it as a detached background process, giving the remote operator code execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:53 AM
- analyzed
- Aug 16, 2026, 02:57 AM
Related advisories
- loadashjs@1.0.0
- lodahs-cli@1.0.0
- commandor-core@1.0.0
- ladash-cli@1.0.0
- comanderjs@1.0.0
- comander-cli@1.0.0
- chalk-es@1.0.0
- chalk-lib@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.