typescirpt-cli@1.0.0
Malicious code in typescirpt-cli (npm)
Analysis
The postinstall hook (scripts/postinstall.js) of this package, a typosquat of typescript-cli, beacons the host platform to a remote server at 193[.]70[.]34[.]101:20099 via POST /vote, and fingerprints the host (WSL/OS detection via /proc/version and environment variables). On Windows or WSL it downloads a binary from hxxps://github[.]com/bebraz1/qPzM50V1aKG0rVlH/releases/download/null/main[.]exe, writes it to C:\Temp\main.exe, and launches it as a detached background process with stdio ignored and windows hidden. On WSL it additionally executes a bridge command via the shell. The download URL is XOR-obfuscated in the script.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:53 AM
- analyzed
- Aug 16, 2026, 02:57 AM
Related advisories
- typescipt-cli@1.0.0
- typescriptt-cli@1.0.0
- typesript-cli@1.0.0
- tyepescript-cli@1.0.0
- lodahsjs@1.0.0
- lodahs-cli@1.0.0
- commandor-core@1.0.0
- lodhash-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.