LWA-2026-11370 confirmed malware

typecript-cli@1.0.0

Malicious code in typecript-cli (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1027 · Obfuscated Files or Information

Analysis

typecript-cli is a typosquat of the TypeScript CLI. Its postinstall hook (scripts/postinstall.js) XOR-obfuscates its payload strings. On install it POSTs a platform fingerprint to the hardcoded endpoint 193[.]70[.]34[.]101:20099/vote, then on Windows and WSL hosts downloads a binary from hxxps://github[.]com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main[.]exe and executes it as a detached background process, writing it to C:\Temp\main.exe. The download URL and C2 host are hidden behind XOR encoding with key 'stf2026'.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:53 AM
analyzed
Aug 16, 2026, 03:02 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.