typescriptt-cli@1.0.0
Malicious code in typescriptt-cli (npm)
Analysis
The postinstall hook of typescriptt-cli (a typosquat of the typescript package) runs a script that fingerprints the host (platform, architecture, Node version, WSL detection) and POSTs it to 193[.]70[.]34[.]101:20099/vote. It then XOR-decodes a GitHub-hosted binary URL, downloads the binary to the temp directory as main.exe, and spawns it detached so it runs in the background. On WSL/Windows it executes a decoded bridge command to launch the downloaded payload. The package ships no actual CLI functionality; its only behaviour is the install-time download-and-execute of a remote binary and beaconing to the C2 host.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:53 AM
- analyzed
- Aug 16, 2026, 02:57 AM
Related advisories
- typesript-cli@1.0.0
- tyepescript-cli@1.0.0
- lodahsjs@1.0.0
- lodahs-cli@1.0.0
- commandor-core@1.0.0
- lodhash-cli@1.0.0
- chalk-core@1.0.0
- comander-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.