LWA-2026-6017 MAL-2026-6525 ↗ confirmed malware

ts-einkle-slot@0.0.8

Malicious code in ts-einkle-slot (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

ts-einkle-slot@0.0.8 is a trojanized clone of the popular big.js decimal arithmetic library. It copies the real library's source, README, repository URL, and author identity (Michael Mclaughlin) but inserts a backdoor at line 606 in both big.js and big.mjs: the code calls `require("node-slot")` and invokes `doc.from_str()` on load, executing when any application imports the package. It also depends on ts-einkle (known malware from the same publisher), creating a two-stage attack chain via the dependency tree. The package has no repository, no lifecycle hooks, and the injected code runs silently — the try/catch block suppresses errors.

analyzed by
Leitwacht
first seen
Jun 26, 2026, 03:32 PM
analyzed
Jun 26, 2026, 03:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.