LWA-2026-11372 confirmed malware

typecript-core@1.0.0

Malicious code in typecript-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (scripts/postinstall.js) of this package, which typosquats the name of a popular TypeScript package, performs two actions. First, it POSTs a host fingerprint (node version, architecture, platform) as JSON to the remote endpoint 193[.]70[.]34[.]101:20099/vote. Second, on Windows and WSL hosts it XOR-decodes a GitHub release URL (hxxps://github[.]com/beebraz1/qzM50V1AKG0rVlH/release/download/null/main[.]exe), downloads the binary main.exe into the temp directory, and launches it as a detached background process with stdio ignored. The downloaded binary is executed without user consent.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:54 AM
analyzed
Aug 16, 2026, 03:00 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.