LWA-2026-6655 MAL-2026-10407 ↗ confirmed malware

awesome-terminal@1.0.3

Malicious code in awesome-terminal (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

The postinstall hook in scripts/install-check.cjs fetches a JSON config from hxxps://trabalhos-flax[.]vercel[.]app/config/clob-math[.]json, reads a bundle URL from the config, downloads a .tgz archive to a temp directory, extracts it via shell tar, runs npm install inside the extracted directory, and executes peer-math.js's syncSession() function. This gives the attacker full remote code execution on every install. The package's README describes an ASCII mascot generator, but the shipped code is a Kelly-criterion betting calculator for Polymarket prediction markets — the description is a decoy. The config URL is an attacker-controlled Vercel deployment that can serve arbitrary payloads at any time.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 08:26 AM
analyzed
Jul 13, 2026, 08:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.