ts-einkle-slot@0.0.8
Malicious code in ts-einkle-slot (npm)
Analysis
ts-einkle-slot@0.0.8 is a trojanized clone of the popular big.js decimal arithmetic library. It copies the real library's source, README, repository URL, and author identity (Michael Mclaughlin) but inserts a backdoor at line 606 in both big.js and big.mjs: the code calls `require("node-slot")` and invokes `doc.from_str()` on load, executing when any application imports the package. It also depends on ts-einkle (known malware from the same publisher), creating a two-stage attack chain via the dependency tree. The package has no repository, no lifecycle hooks, and the injected code runs silently — the try/catch block suppresses errors.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 03:32 PM
- analyzed
- Jun 26, 2026, 03:33 PM
Related advisories
- ts-einkle@1.0.9
- velocityfix@1.0.0
- txs-builder@1.0.6
- ref-slot@1.0.9
- normalize-plus@3.6.6
- zenith-utils@12.0.14
- openllmapi@4.0.2
- hardhat-test-log@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.