LWA-2026-11360 confirmed malware
typescriptt-core@1.0.0
Malicious code in typescriptt-core (npm)
T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1082 · System Information Discovery
Analysis
The postinstall hook (scripts/postinstall.js) runs on install and beacons host telemetry (platform, node version, CPU arch) via HTTP POST to 193[.]70[.]34[.]101:20099/vote. On Windows and WSL hosts it additionally XOR-decodes an obfuscated URL, downloads a binary to %TEMP%\main.exe, and executes it as a detached background process (stdio ignored, window hidden), or runs a bridge command via exec. The package name is a typosquat of the legitimate 'typescript' package.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:54 AM
- analyzed
- Aug 16, 2026, 03:01 AM
Related advisories
- comander-lib@1.0.0
- typesript-core@1.0.0
- raectjs@1.0.0
- typescirpt-cli@1.0.0
- typescipt-cli@1.0.0
- typescriptt-cli@1.0.0
- typesript-cli@1.0.0
- tyepescript-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.