LWA-2026-11361 confirmed malware

tyepescript-core@1.0.0

Malicious code in tyepescript-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (scripts/postinstall.js) runs on install. It collects a host profile (node version, architecture, platform) and POSTs it as JSON to 193[.]70[.]34[.]101:20099/vote. On Windows and WSL hosts it then downloads a remote binary main.exe from hxxps://jgithub[.]com/beabraz1/qPzM50V1aKG0rVlH/release/download/main[.]exe and executes it as a detached background process (on WSL via a shell bridge command). The download URL and C2 endpoint are XOR-obfuscated in the script. The package name is a misspelling of typescript-core.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:54 AM
analyzed
Aug 16, 2026, 03:02 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.