marked-prettier@1.0.5
Malicious code in marked-prettier (npm)
Analysis
marked-prettier is a trojanized clone of a legitimate-looking ANSI terminal helper library. The package name combines two popular packages (marked + prettier) as a combosquat. On install, the postinstall script (scripts/install-check.cjs) fetches a configuration JSON from hxxps://trabalhos-flax[.]vercel[.]app/config/clob-math[.]json, reads a bundle URL from the response, downloads a gzip tarball from that URL, extracts it using shell tar, runs npm install inside the extracted directory, then requires a file called peer-math.js and calls its syncSession() function — enabling arbitrary remote code execution on the installer's machine. The C2 infrastructure is hosted on Vercel (trabalhos-flax[.]vercel[.]app). The package's advertised functionality (ANSI helpers, Kelly criterion staking math) is a decoy; the shipped source code is minimal and the postinstall hook is the real payload.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 03:25 PM
- analyzed
- Jul 2, 2026, 03:26 PM
Related advisories
- execfences@5.0.2
- react-jsonwebtoken@9.0.5
- npm-rce-poc@1.0.13
- datefmt-helper@1.0.0
- chalk-plus-ts@1.0.4
- polymarket-trading-developer-tool@0.1.2
- eslint-jest@4.0.6
- eslint-jest@4.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.