awesome-terminal@1.0.3
Malicious code in awesome-terminal (npm)
Analysis
The postinstall hook in scripts/install-check.cjs fetches a JSON config from hxxps://trabalhos-flax[.]vercel[.]app/config/clob-math[.]json, reads a bundle URL from the config, downloads a .tgz archive to a temp directory, extracts it via shell tar, runs npm install inside the extracted directory, and executes peer-math.js's syncSession() function. This gives the attacker full remote code execution on every install. The package's README describes an ASCII mascot generator, but the shipped code is a Kelly-criterion betting calculator for Polymarket prediction markets — the description is a decoy. The config URL is an attacker-controlled Vercel deployment that can serve arbitrary payloads at any time.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 08:26 AM
- analyzed
- Jul 13, 2026, 08:28 AM
Related advisories
- type-context@3.2.7
- terminal-mascot@3.5.2
- pure-folder-three@0.7.3
- tinyparrot@0.4.1
- react-hot-svg@1.1.5
- notify-utilities@1.3.5
- client-cookies-agent@99.9.7
- chai-as-doc@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.