ts-await@3.1.8
Malicious code in ts-await (npm)
Analysis
ts-await@3.1.8 is a trojanized clone of the pino logger package that downloads and executes remote code. When the module is imported, index.js spawns a detached child process running lib/caller.js. That file fetches a second-stage payload from an IPFS gateway (peach-eligible-penguin-917[.]mypinata[.]cloud, CID bafkreigjnxn5vnn34rc5r43ajwwkmk4akqpm4awmq5gdhakgszpeqiffsu) using the HTTP header x-secret-key: _. The response's cookie field is executed via the Function constructor with full Node.js require access, giving the attacker arbitrary code execution on the installer's machine. The fetch retries up to 5 times and suppresses console output during the operation.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 08:08 PM
- analyzed
- Jul 7, 2026, 08:10 PM
Related advisories
- url-func-registry@1.0.4
- @vite-ln/build-ts@5.17.0
- chain-async-dom@1.3.6
- @vite-tab/tab@5.7.0
- tipsen-last@1.0.0
- react-next-vite@1.2.9
- mongoose-schema-unique@4.0.4
- motion-pull@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.