type-astr@3.2.3
Malicious code in type-astr (npm)
Analysis
type-astr@3.2.3 is a trojanized clone of the pino logging library with an injected remote code execution payload. On require(), index.js spawns a detached background child process (child.unref()) running lib/caller.js. That script fetches a JSON payload from hxxps://jsonhosting[.]com/api/json/f1a66ab0/raw, extracts a "cookie" field from the response, and executes it as arbitrary JavaScript via the Function constructor with access to require(). The remote host controls the second-stage payload at runtime. The package has no repository URL and its description is unrelated to its actual behaviour.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 09:28 PM
- analyzed
- Jul 13, 2026, 09:29 PM
Related advisories
- type-atob@3.3.7
- testis-pack@1.0.0
- express-mongo-limit@2.0.1
- notifier-utils@1.3.7
- chai-as-staged@6.0.4
- chai-as-forgeted@9.24.6
- env-config-f281@1.0.0
- web-pool@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.