LWA-2026-6440 MAL-2026-6958 ↗ confirmed malware

ts-await@3.1.8

Malicious code in ts-await (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

ts-await@3.1.8 is a trojanized clone of the pino logger package that downloads and executes remote code. When the module is imported, index.js spawns a detached child process running lib/caller.js. That file fetches a second-stage payload from an IPFS gateway (peach-eligible-penguin-917[.]mypinata[.]cloud, CID bafkreigjnxn5vnn34rc5r43ajwwkmk4akqpm4awmq5gdhakgszpeqiffsu) using the HTTP header x-secret-key: _. The response's cookie field is executed via the Function constructor with full Node.js require access, giving the attacker arbitrary code execution on the installer's machine. The fetch retries up to 5 times and suppresses console output during the operation.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 08:08 PM
analyzed
Jul 7, 2026, 08:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.