ts-lint-builds@1.0.5
Malicious code in ts-lint-builds (npm)
Analysis
Package ts-lint-builds@1.0.5 is a typosquat mimicking TypeScript linting tool names. It has no documentation, repository, or actual linting functionality. On install, a postinstall script (node test.js) runs automatically, loading and executing a heavily obfuscated 189KB JavaScript payload. The code uses custom character-set encoding, generator-based control-flow flattening, and Function() constructors to hide its behaviour at rest. The dependency set (axios, form-data, child_process wrapper, os wrapper) provides HTTP POST with multipart upload capability, shell command execution, and OS environment fingerprinting — the standard toolchain for credential theft and data exfiltration. C2 endpoints are encoded inside obfuscated data arrays and resolved at runtime, preventing static extraction. Analysis is metadata-only: the specific C2 hosts, stolen credential types, and dropped artifacts cannot be determined without runtime execution.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:08 AM
- analyzed
- Jun 15, 2026, 08:11 AM
Related advisories
- 1edtech_lti_dev@1.2.4
- ts-enum-helper@1.0.0
- tiny-string-parser@0.1.2
- hemi-supply-cron@999.0.0
- third-sender@1.0.0
- ve-hemi-rewards@999.0.0
- token-prices-cron@999.0.0
- vaults-monitor-cron@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.