ts-numbering@1.0.0
Malicious code in ts-numbering (npm)
Analysis
ts-numbering@1.0.0 is a trojanized clone of the legitimate big.js arbitrary-precision decimal arithmetic library. The attacker copied big.js v7.0.1 verbatim and injected a malicious block into both big.js and big.mjs at line 605-609: a try/catch that requires the package 'parket-helper' and calls its from_str() method (returning a promise, suggesting string-decoded payload execution). This injected code runs in module scope whenever a project imports the package — no install hook needed. The package also declares a dependency on the known-malware package 'local-ip-helper'. Both helper packages form a multi-package supply-chain attack chain delivering an executable payload at runtime.
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 01:54 PM
- analyzed
- Jun 20, 2026, 01:55 PM
Related advisories
- local-ip-helper@0.1.0
- twilio-voice-js-reference-components@1.0.1
- anthropic-claude-latest@4.7.1
- ts-bn-lint-helper@3.1.19
- llm-traces-app@1.0.1
- atlasora-client@1.0.0
- atlasora-utils@1.0.0
- atlasora-types@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.