type-context@3.2.7
Malicious code in type-context (npm)
Analysis
type-context@3.2.7 is a trojanized package that executes remote code on import. The main entry point (index.js) spawns a detached background Node.js process running lib/caller.js. That script fetches JavaScript code from hxxps://json[.]extendsclass[.]com/bin/250fca079abb (with header x-secret-key: _) and executes it via the Function constructor, retrying up to 5 times on failure. The fetched payload is fully attacker-controlled, enabling arbitrary remote code execution on any system that requires this package. A secondary URL (hxxps://jsonkeeper[.]com/b/XRFG3) is also embedded in base64-encoded form.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 08:26 AM
- analyzed
- Jul 13, 2026, 08:27 AM
Related advisories
- terminal-mascot@3.5.2
- pure-folder-three@0.7.3
- tinyparrot@0.4.1
- react-hot-svg@1.1.5
- notify-utilities@1.3.5
- client-cookies-agent@99.9.7
- chai-as-doc@2.3.5
- llama-tokenizer@1.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.