@schemats/json-schema-to-typescript@15.0.4
Malicious code in @schemats/json-schema-to-typescript (npm)
Analysis
This package masquerades as the popular json-schema-to-typescript library, copying its metadata and legitimate code, but its CLI entrypoint (the json2ts bin, dist/src/cli.js) contains an injected, string-obfuscated routine that runs on every invocation. On macOS, and only when the current username contains a specific substring, it reads the local iMessage/SMS database at ~/Library/Messages/chat.db and uploads it as a multipart form POST to a remote server (json2ts[.]dylib[.]io, port 3000) using a hardcoded Basic auth credential. Failures are disguised as a benign Full Disk Access prompt. This is targeted theft of private message history.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 07:13 PM
- analyzed
- Jun 17, 2026, 09:55 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.