LWA-2026-6727 MAL-2026-10512 ↗ confirmed malware

type-unique@3.1.3

Malicious code in type-unique (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1055 · Process Injection

Analysis

type-unique@3.1.3 is a staged remote code execution downloader. On require(), index.js spawns lib/caller.js as a detached background process. caller.js fetches a remote JSON payload from hxxps://jsonhosting[.]com/api/json/3ea04c38/raw (with HTTP header x-secret-key: _), extracts a "cookie" value from the response, and executes it as arbitrary JavaScript via the Function constructor. This enables the attacker to run arbitrary commands on the installer's machine by updating the remote JSON payload. The package has no repository and its description is unrelated to its actual behaviour.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 09:50 PM
analyzed
Jul 13, 2026, 09:51 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.