LWA-2026-6654 MAL-2026-10440 ↗ confirmed malware

type-context@3.2.7

Malicious code in type-context (npm)

Analysis

type-context@3.2.7 is a trojanized package that executes remote code on import. The main entry point (index.js) spawns a detached background Node.js process running lib/caller.js. That script fetches JavaScript code from hxxps://json[.]extendsclass[.]com/bin/250fca079abb (with header x-secret-key: _) and executes it via the Function constructor, retrying up to 5 times on failure. The fetched payload is fully attacker-controlled, enabling arbitrary remote code execution on any system that requires this package. A secondary URL (hxxps://jsonkeeper[.]com/b/XRFG3) is also embedded in base64-encoded form.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 08:26 AM
analyzed
Jul 13, 2026, 08:27 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.