ts-big-ecro@3.8.1
Malicious code in ts-big-ecro (npm)
Analysis
ts-big-ecro@3.8.1 is a combosquat of the legitimate big.js library, published under the impersonating handle d.ani.el.laba.l.d.ivi.no. It contains no malicious code itself but declares a hard dependency on server-parket@^3.8.1, a credential-stealing package. Upon npm install, server-parket's postinstall hook executes and performs broad system scanning: it enumerates home directories on Linux (/home/*, $HOME), drives C-J on Windows, and /Users/* on macOS, recursively searching for cryptocurrency wallet files (keywords: sol, eth, btc, metamask, phantom, mnemonic, seed, trezor, keystore, private_key), .env files containing API keys and tokens, and configuration files (id.json, config.toml). It also reads shell history from .bash_history, .zsh_history, fish_history, and PowerShell ConsoleHost_history.txt. On Windows and macOS it packs and exfiltrates Telegram Desktop's tdata directory containing session credentials. All harvested data is uploaded as multipart/form-data to backend-helper-service[.]vercel[.]app/api/v1. The package was published and rapidly unpublished to evade detection.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 08:28 AM
- analyzed
- Jun 19, 2026, 08:29 AM
Related advisories
- node-slot@1.0.7
- server-parket@3.8.1
- parket-helper@0.0.1
- tiny-string-parser@0.1.2
- system-drive@1.0.0
- snavbox@1.0.1
- renovate-config-doctolib@9.9.16
- coral-wraith@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.