LWA-2026-6555 MAL-2026-10077 ↗ confirmed malware

type-slint@3.3.7

Malicious code in type-slint (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

type-slint@3.3.7 is a combosquat of the pino logging library. On require, it spawns a detached background process that fetches arbitrary JavaScript from an IPFS gateway and executes it via the Function constructor, giving the attacker full remote code execution on the installer's machine. The second-stage payload is fetched from hxxps://bronze-improved-gibbon-411[.]mypinata[.]cloud/ipfs/bafkreigjnxn5vnn34rc5r43ajwwkmk4akqpm4awmq5gdhakgszpeqiffsu. No token or credential theft was observed in the first-stage code, but the dynamic payload can perform any action.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 01:08 PM
analyzed
Jul 9, 2026, 01:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.