chalk-plus-ts@1.0.4
Malicious code in chalk-plus-ts (npm)
Analysis
chalk-plus-ts is a combosquat of the popular 'chalk' package. On npm install, the postinstall hook (node lib/utils/index.js) spawns a detached Node.js process that reads a padded LICENSE file, then fetches a remote payload from api[.]jsonbin[.]io/v3/b/6a461991f5f4af5e295272d4 and executes it via new Function() — a remote code execution dropper. The fetched payload runs with full access to the 'require' function, enabling arbitrary code execution in the installer's context. The package has no repository, no verifiable publisher identity, and impersonates the nodemailer ecosystem.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 08:27 AM
- analyzed
- Jul 2, 2026, 10:56 AM
Related advisories
- chalk-plus-ts@1.0.3 same package
- assertcoreutils@2.3.2
- pino-zod@1.0.121
- zod-pino@1.0.122
- panrouter-admin@5.0.0
- hex-conv-ae7a@1.0.0
- ordered-btree@3.2.2
- check-ulid@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.