LWA-2026-6610 MAL-2026-10189 ↗ confirmed malware

tinymask-js@1.0.2

Malicious code in tinymask-js (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

tinymask-js is a typosquat of the real tinymask package. On require(), it downloads a binary from filament-zap[.]vercel[.]app/service/assets/fetchLinuxBinary (Linux) or fetchBinary (Windows) to ~/.local/share/WinMetrics/WinMetrics (Linux) or %LOCALAPPDATA%\Programs\WinMetrics\WinService.exe (Windows), then spawns it as a detached background process. The package re-exports the real tinymask as a facade to hide its activity.

analyzed by
Leitwacht
first seen
Jul 11, 2026, 08:38 AM
analyzed
Jul 11, 2026, 08:39 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.