tsliverhome@1.1.5
Malicious code in tsliverhome (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer
Analysis
Package tsliverhome combosquats Microsoft's tslib TypeScript helper library. Its index.js exports a function that fetches content from hxxps://verceljs-kappa[.]vercel[.]app/icons/23 and runs eval(JSON.parse(body)) on the response, allowing the attacker to serve arbitrary code for remote execution. The README and description are copied from the legitimate tslib package to deceive installers.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:08 AM
- analyzed
- Jun 15, 2026, 08:12 AM
Related advisories
- trgrip@1.0.4
- transform-es2015-destructuring@6.24.1
- texttweak-kit@1.0.0
- stylelint-standard@1.2.0
- sisubeny-bun-pwn-payload-1@1.0.0
- codyx-ai@1.14.42
- rollup-packages-polyfill-core@0.5.0
- houzidawang808@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.