LWA-2026-6605 MAL-2026-10164 ↗ confirmed malware

type-async@3.3.7

Malicious code in type-async (npm)

Analysis

type-elint@3.3.7, type-plint@3.3.7, and type-async@3.3.7 are trojanized clones of the pino logger. On require(), each spawns lib/caller.js as a detached background process. caller.js fetches a remote payload from hxxps://json[.]extendsclass[.]com/bin/{uuid} (type-elint: 863e90480800, type-plint: 26d6d7d075e1, type-async: 250fca079abb) and executes it via the Function constructor, giving the remote payload full access to Node.js require(). The package names combosquat the real type-* ecosystem.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 06:03 PM
analyzed
Jul 10, 2026, 10:33 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.