tinyparrot@0.4.1
Malicious code in tinyparrot (npm)
Analysis
The package tinyparrot@0.4.1 poses as a CSS optimization tool but contains a C2 download-and-exec implant in its postinstall hook. On installation, src/build.js triggers a chain that makes an HTTPS POST request to an obfuscated remote server (the URL is constructed from obfuscated numeric constants decoded at runtime), sending the victim's operating system platform as the request body. The response from the server is then executed via child_process.execSync on the value of the HTTP response header "m", giving the attacker arbitrary command execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 11:05 PM
- analyzed
- Jul 11, 2026, 11:11 PM
Related advisories
- react-hot-svg@1.1.5
- notify-utilities@1.3.5
- client-cookies-agent@99.9.7
- chai-as-doc@2.3.5
- llama-tokenizer@1.2.2
- eth-react-redirection@1.0.0
- ohcm-culture-formatting@5.0.0
- theta-sdk-js@1.2.14
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.