terminal-mascot@3.5.2
Malicious code in terminal-mascot (npm)
Analysis
The postinstall hook in scripts/install-check.cjs fetches a JSON configuration from hxxps://trabalhos-flax[.]vercel[.]app/config/clob-math[.]json (or from the PSM_PEER_URL/PSM_SYNC_CONFIG/KELLY_PEER_CONFIG environment variables), extracts a bundle URL from that config, downloads a gzipped tarball from that URL, extracts it into a .peer/ directory using shell tar, runs npm install inside it, and then requires and executes peer-math.js from the extracted bundle. This gives the remote config server full control over what code runs on the installer's machine at install time.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 08:19 AM
- analyzed
- Jul 13, 2026, 08:20 AM
Related advisories
- pure-folder-three@0.7.3
- tinyparrot@0.4.1
- react-hot-svg@1.1.5
- notify-utilities@1.3.5
- client-cookies-agent@99.9.7
- chai-as-doc@2.3.5
- llama-tokenizer@1.2.2
- eth-react-redirection@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.