LWA-2026-11353 confirmed malware

typescriptt-cli@1.0.0

Malicious code in typescriptt-cli (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook of typescriptt-cli (a typosquat of the typescript package) runs a script that fingerprints the host (platform, architecture, Node version, WSL detection) and POSTs it to 193[.]70[.]34[.]101:20099/vote. It then XOR-decodes a GitHub-hosted binary URL, downloads the binary to the temp directory as main.exe, and spawns it detached so it runs in the background. On WSL/Windows it executes a decoded bridge command to launch the downloaded payload. The package ships no actual CLI functionality; its only behaviour is the install-time download-and-execute of a remote binary and beaconing to the C2 host.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:53 AM
analyzed
Aug 16, 2026, 02:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.