type-swap@3.1.3
Malicious code in type-swap (npm)
Analysis
type-swap@3.1.3 is a trojanized clone of the pino logger package. On require(), index.js spawns a detached child process running lib/caller.js. That script fetches attacker-controlled content from hxxps://jsonhosting[.]com/api/json/e16583b1/raw, extracts a "cookie" value from the JSON response, and executes it as arbitrary code via the Function constructor with access to Node.js require(). The remote payload can perform any action including credential theft, data exfiltration, or backdoor installation. The package's README is a verbatim copy of the legitimate pino logger documentation, but the package name and code are unrelated.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 09:44 PM
- analyzed
- Jul 13, 2026, 09:45 PM
Related advisories
- monitoring-service-util@1.0.0
- type-astr@3.2.3
- chai-as-verified@7.1.5
- polymarket-stake-kelly-math-check@3.5.2
- route-processor@3.1.5
- font-huge@2.5.3
- polymarket-stake-kelly-math@3.8.2
- polymarket-math-stake-kelly@3.7.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.