ttspc-server-sample@9.0.0
Malicious code in ttspc-server-sample (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Credential-theft malware masquerading as a "worker-build PoC" package. The postinstall hook runs main.js, which collects host system information (hostname, platform, CPU count, memory, username, cwd) and steals environment-variable credentials targeting AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, NPM_TOKEN, GITHUB_TOKEN, GITLAB_TOKEN, and database connection strings. All of it is exfiltrated to an oastify[.]com (Burp Collaborator) callback host via HTTP POST to /exfil and /api/exfil, plus DNS exfiltration via dns.lookup.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 11:29 AM
- analyzed
- Jun 12, 2026, 11:30 AM
Related advisories
- polymarket-onchain-plugin@2.1.3
- polymarket-ai-agent@0.1.0
- polygon-bitquery-apis@2.2.3
- pocbitbarrontest@1.0.0
- pino-sdk-v2@9.9.0
- pino-pretty-logs@1.1.0
- pino-pretty-logger@1.1.1
- pino-formatter@1.1.12
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.