LWA-2026-11373 confirmed malware
typescipt-core@1.0.0
Malicious code in typescipt-core (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (scripts/postinstall.js) fingerprints the host (node version, architecture, platform, WSL detection) and POSTs the platform profile as JSON to the hardcoded C2 endpoint hxxp://193[.]70[.]34[.]101:20099/vote. On Windows and WSL it then downloads a second-stage binary from a GitHub-hosted asset URL (github[.]com/beebraz1/qzM50V1AKG0rVlH/release/...) into %TEMP%/main.exe and launches it as a detached background process with stdio ignored, so it outlives the install. The package name is a misspelling of the legitimate "typescript-core".
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:54 AM
- analyzed
- Aug 16, 2026, 03:01 AM
Related advisories
- comander-lib@1.0.0
- axois-http@1.0.0
- typscript-core@1.0.0
- typscript-cli@1.0.0
- typescipt-cli@1.0.0
- loadashjs@1.0.0
- lodahs-cli@1.0.0
- commandor-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.