tinymask-js@1.0.2
Malicious code in tinymask-js (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
tinymask-js is a typosquat of the real tinymask package. On require(), it downloads a binary from filament-zap[.]vercel[.]app/service/assets/fetchLinuxBinary (Linux) or fetchBinary (Windows) to ~/.local/share/WinMetrics/WinMetrics (Linux) or %LOCALAPPDATA%\Programs\WinMetrics\WinService.exe (Windows), then spawns it as a detached background process. The package re-exports the real tinymask as a facade to hide its activity.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 08:38 AM
- analyzed
- Jul 11, 2026, 08:39 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.