LWA-2026-11356 confirmed malware

typscript-core@1.0.0

Malicious code in typscript-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1059 · Command and Scripting Interpreter

Analysis

The postinstall hook (scripts/postinstall.js) of this package, which typosquats the name "typescript-core", POSTs host OS/platform information to 193[.]70[.]34[.]101:20099/vote. On Windows and WSL hosts it additionally downloads a binary main.exe from github[.]com/beebraz1/qzM5V1AKG0rVlH/releases/download/null/main.exe and executes it as a detached background process (stdio ignored, unref'd), and fingerprints the host via /proc/version and WSL environment variables.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:53 AM
analyzed
Aug 16, 2026, 02:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.