tslint-conf@7.2.1
Malicious code in tslint-conf (npm)
Analysis
tslint-conf@7.2.1 is a combosquat of the real tslint package. On require(), index.js spawns lib/caller.js as a detached background child process. caller.js fetches a remote payload from an IPFS gateway (hxxps://peach-eligible-penguin-917[.]mypinata[.]cloud/ipfs/bafkreigjnxn5vnn34rc5r43ajwwkmk4akqpm4awmq5gdhakgszpeqiffsu) and executes it via new Function.constructor("require", ...), giving the attacker arbitrary code execution on the installer's machine. The detached spawn with child.unref() allows the parent process to exit while the payload continues running in the background.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 08:38 PM
- analyzed
- Jul 7, 2026, 08:39 PM
Related advisories
- viteplugiin@1.0.28
- express-guardian@1.4.1
- chai-sdk@1.4.7
- zredis-typed@1.0.127
- luludawang-kit@0.0.1
- express-ini@12.1.10
- db-query-log@1.0.2
- @marketfront/fingerprint@7.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.