type-plint@3.3.7
Malicious code in type-plint (npm)
Analysis
type-elint@3.3.7, type-plint@3.3.7, and type-async@3.3.7 are trojanized clones of the pino logger. On require(), each spawns lib/caller.js as a detached background process. caller.js fetches a remote payload from hxxps://json[.]extendsclass[.]com/bin/{uuid} (type-elint: 863e90480800, type-plint: 26d6d7d075e1, type-async: 250fca079abb) and executes it via the Function constructor, giving the remote payload full access to Node.js require(). The package names combosquat the real type-* ecosystem.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 03:38 PM
- analyzed
- Jul 10, 2026, 10:33 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.