LWA-2026-6242 MAL-2026-5710 ↗ confirmed malware

chalk-plus-ts@1.0.4

Malicious code in chalk-plus-ts (npm)

Analysis

chalk-plus-ts is a combosquat of the popular 'chalk' package. On npm install, the postinstall hook (node lib/utils/index.js) spawns a detached Node.js process that reads a padded LICENSE file, then fetches a remote payload from api[.]jsonbin[.]io/v3/b/6a461991f5f4af5e295272d4 and executes it via new Function() — a remote code execution dropper. The fetched payload runs with full access to the 'require' function, enabling arbitrary code execution in the installer's context. The package has no repository, no verifiable publisher identity, and impersonates the nodemailer ecosystem.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 08:27 AM
analyzed
Jul 2, 2026, 10:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.