LWA-2026-5334 MAL-2026-2883 ↗ confirmed malware

ts-lint-builds@1.0.5

Malicious code in ts-lint-builds (npm)

T1059.007 · JavaScriptT1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Package ts-lint-builds@1.0.5 is a typosquat mimicking TypeScript linting tool names. It has no documentation, repository, or actual linting functionality. On install, a postinstall script (node test.js) runs automatically, loading and executing a heavily obfuscated 189KB JavaScript payload. The code uses custom character-set encoding, generator-based control-flow flattening, and Function() constructors to hide its behaviour at rest. The dependency set (axios, form-data, child_process wrapper, os wrapper) provides HTTP POST with multipart upload capability, shell command execution, and OS environment fingerprinting — the standard toolchain for credential theft and data exfiltration. C2 endpoints are encoded inside obfuscated data arrays and resolved at runtime, preventing static extraction. Analysis is metadata-only: the specific C2 hosts, stolen credential types, and dropped artifacts cannot be determined without runtime execution.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 08:08 AM
analyzed
Jun 15, 2026, 08:11 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.