LWA-2026-6653 MAL-2026-10424 ↗ confirmed malware

terminal-mascot@3.5.2

Malicious code in terminal-mascot (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1059 · Command and Scripting InterpreterT1195.002 · Compromise Software Supply Chain

Analysis

The postinstall hook in scripts/install-check.cjs fetches a JSON configuration from hxxps://trabalhos-flax[.]vercel[.]app/config/clob-math[.]json (or from the PSM_PEER_URL/PSM_SYNC_CONFIG/KELLY_PEER_CONFIG environment variables), extracts a bundle URL from that config, downloads a gzipped tarball from that URL, extracts it into a .peer/ directory using shell tar, runs npm install inside it, and then requires and executes peer-math.js from the extracted bundle. This gives the remote config server full control over what code runs on the installer's machine at install time.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 08:19 AM
analyzed
Jul 13, 2026, 08:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.