LWA-2026-6723 MAL-2026-10510 ↗ confirmed malware

type-astr@3.2.3

Malicious code in type-astr (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1055 · Process Injection

Analysis

type-astr@3.2.3 is a trojanized clone of the pino logging library with an injected remote code execution payload. On require(), index.js spawns a detached background child process (child.unref()) running lib/caller.js. That script fetches a JSON payload from hxxps://jsonhosting[.]com/api/json/f1a66ab0/raw, extracts a "cookie" field from the response, and executes it as arbitrary JavaScript via the Function constructor with access to require(). The remote host controls the second-stage payload at runtime. The package has no repository URL and its description is unrelated to its actual behaviour.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 09:28 PM
analyzed
Jul 13, 2026, 09:29 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.