LWA-2026-11358 confirmed malware
typesript-core@1.0.0
Malicious code in typesript-core (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (scripts/postinstall.js) runs on install and POSTs a host-platform fingerprint (node version, arch, platform) to 193[.]70[.]34[.]101:20099/vote. On Windows and WSL hosts it then downloads a second-stage binary from hxxps://github[.]com/bezbaz1/qPzM50V1AKG0rVlH/release/download/null/main[.]exe, writes it to C:\Temp\main.exe, and executes it as a detached background process (windowsHide:true, unref'd). The download URL and C2 address are XOR-obfuscated in the script. The package name is a misspelling of the legitimate typescript-core package.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:54 AM
- analyzed
- Aug 16, 2026, 03:00 AM
Related advisories
- raectjs@1.0.0
- typescirpt-cli@1.0.0
- typescipt-cli@1.0.0
- typescriptt-cli@1.0.0
- typesript-cli@1.0.0
- tyepescript-cli@1.0.0
- lodahsjs@1.0.0
- lodahs-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.