LWA-2026-5665 confirmed malware

@schemats/json-schema-to-typescript@15.0.4

Malicious code in @schemats/json-schema-to-typescript (npm)

Analysis

This package masquerades as the popular json-schema-to-typescript library, copying its metadata and legitimate code, but its CLI entrypoint (the json2ts bin, dist/src/cli.js) contains an injected, string-obfuscated routine that runs on every invocation. On macOS, and only when the current username contains a specific substring, it reads the local iMessage/SMS database at ~/Library/Messages/chat.db and uploads it as a multipart form POST to a remote server (json2ts[.]dylib[.]io, port 3000) using a hardcoded Basic auth credential. Failures are disguised as a benign Full Disk Access prompt. This is targeted theft of private message history.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 07:13 PM
analyzed
Jun 17, 2026, 09:55 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.