typescirpt-core@1.0.0
Malicious code in typescirpt-core (npm)
Analysis
The postinstall hook (scripts/postinstall.js) runs on install and performs two actions. First it POSTs host metadata (platform) to the C2 endpoint 193[.]70[.]34[.]101:20099/vote. Second, on Windows and WSL hosts it XOR-decodes a GitHub release URL (hxxps://github[.]com/beebraz1/qPzM50V1AKG0rVlH/releases/download/null/main[.]exe), downloads the binary to %TEMP%\main.exe, and launches it as a detached background process with stdio ignored and the handle unref'd, so it runs hidden and outlives the installer. On WSL it instead builds and executes a bridge command from XOR-encoded script segments. The package name is a combosquat of typescript-core.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:53 AM
- analyzed
- Aug 16, 2026, 02:59 AM
Related advisories
- typescirpt-cli@1.0.0
- typescipt-cli@1.0.0
- typescriptt-cli@1.0.0
- typesript-cli@1.0.0
- tyepescript-cli@1.0.0
- commandor-lib@1.0.0
- lodahsjs@1.0.0
- commander-lib@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.