LWA-2026-5339 MAL-2026-3775 ↗ confirmed malware

tsliverhome@1.1.5

Malicious code in tsliverhome (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

Package tsliverhome combosquats Microsoft's tslib TypeScript helper library. Its index.js exports a function that fetches content from hxxps://verceljs-kappa[.]vercel[.]app/icons/23 and runs eval(JSON.parse(body)) on the response, allowing the attacker to serve arbitrary code for remote execution. The README and description are copied from the legitimate tslib package to deceive installers.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 08:08 AM
analyzed
Jun 15, 2026, 08:12 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.