LWA-2026-11354 confirmed malware

typesript-cli@1.0.0

Malicious code in typesript-cli (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (scripts/postinstall.js) of this package, a typosquat of typescript-cli, beacons host metadata (platform, architecture, Node version, WSL detection) to 193[.]70[.]34[.]101:20099/vote via HTTP POST. On Windows/WSL hosts it additionally downloads a second-stage binary from hxxps://github[.]com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main[.]exe into the temp directory and executes it as a detached, hidden background process (spawn with detached:true, stdio ignored, windowsHide), or runs a bridge command via child_process.exec. The C2 endpoint and binary URL are XOR-obfuscated in the script.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:53 AM
analyzed
Aug 16, 2026, 02:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.