type-unique@3.1.3
Malicious code in type-unique (npm)
Analysis
type-unique@3.1.3 is a staged remote code execution downloader. On require(), index.js spawns lib/caller.js as a detached background process. caller.js fetches a remote JSON payload from hxxps://jsonhosting[.]com/api/json/3ea04c38/raw (with HTTP header x-secret-key: _), extracts a "cookie" value from the response, and executes it as arbitrary JavaScript via the Function constructor. This enables the attacker to run arbitrary commands on the installer's machine by updating the remote JSON payload. The package has no repository and its description is unrelated to its actual behaviour.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 09:50 PM
- analyzed
- Jul 13, 2026, 09:51 PM
Related advisories
- type-astr@3.2.3
- type-atob@3.3.7
- testis-pack@1.0.0
- express-mongo-limit@2.0.1
- notifier-utils@1.3.7
- chai-as-staged@6.0.4
- chai-as-forgeted@9.24.6
- env-config-f281@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.