LWA-2026-11369 confirmed malware
typscript-cli@1.0.0
Malicious code in typscript-cli (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter
Analysis
The postinstall hook (scripts/postinstall.js) runs on install. It fingerprints the host (platform, architecture, WSL/virtualization detection via /proc/version and /proc/sys/kernel/osrelease) and POSTs the platform label as JSON to the C2 endpoint hxxp://193[.]70[.]34[.]101:20099/vote. It then XOR-decodes an obfuscated URL and downloads a remote binary, writing it to %TEMP%\main.exe and launching it detached on Windows, or executing a bridge launcher via the shell on WSL/Linux. The package name typscript-cli is a misspelling of the legitimate typescript-cli.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:52 AM
- analyzed
- Aug 16, 2026, 02:57 AM
Related advisories
- typescipt-cli@1.0.0
- loadashjs@1.0.0
- lodahs-cli@1.0.0
- commandor-core@1.0.0
- ladash-cli@1.0.0
- comanderjs@1.0.0
- comander-cli@1.0.0
- commandor-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.