LWA-2026-5758 MAL-2026-6199 ↗ confirmed malware

ts-big-ecro@3.8.1

Malicious code in ts-big-ecro (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1552.004 · Private KeysT1083 · File and Directory DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

ts-big-ecro@3.8.1 is a combosquat of the legitimate big.js library, published under the impersonating handle d.ani.el.laba.l.d.ivi.no. It contains no malicious code itself but declares a hard dependency on server-parket@^3.8.1, a credential-stealing package. Upon npm install, server-parket's postinstall hook executes and performs broad system scanning: it enumerates home directories on Linux (/home/*, $HOME), drives C-J on Windows, and /Users/* on macOS, recursively searching for cryptocurrency wallet files (keywords: sol, eth, btc, metamask, phantom, mnemonic, seed, trezor, keystore, private_key), .env files containing API keys and tokens, and configuration files (id.json, config.toml). It also reads shell history from .bash_history, .zsh_history, fish_history, and PowerShell ConsoleHost_history.txt. On Windows and macOS it packs and exfiltrates Telegram Desktop's tdata directory containing session credentials. All harvested data is uploaded as multipart/form-data to backend-helper-service[.]vercel[.]app/api/v1. The package was published and rapidly unpublished to evade detection.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 08:28 AM
analyzed
Jun 19, 2026, 08:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.