type-slint@3.3.7
Malicious code in type-slint (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
type-slint@3.3.7 is a combosquat of the pino logging library. On require, it spawns a detached background process that fetches arbitrary JavaScript from an IPFS gateway and executes it via the Function constructor, giving the attacker full remote code execution on the installer's machine. The second-stage payload is fetched from hxxps://bronze-improved-gibbon-411[.]mypinata[.]cloud/ipfs/bafkreigjnxn5vnn34rc5r43ajwwkmk4akqpm4awmq5gdhakgszpeqiffsu. No token or credential theft was observed in the first-stage code, but the dynamic payload can perform any action.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 01:08 PM
- analyzed
- Jul 9, 2026, 01:10 PM
Related advisories
- chai-as-smart@2.3.5
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- mchain-sdk@4.2.5
- @playerdata-internal/playerdata-core@9999.99.20
- testudo-pack@1.0.0
- configration@2.3.5
- express-mongo-limit@2.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.