LWA-2026-6891 MAL-2026-10990 ↗ confirmed malware

ts-vitest@1.1.1

Malicious code in ts-vitest (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

ts-vitest is a combosquat of the legitimate ts-jest package. On install, the postinstall hook (scripts/install-check.cjs) fetches a JSON configuration from hxxps://ts-eslint[.]vercel[.]app/config/clob-math[.]json, extracts a bundle URL from that config, downloads a .tgz archive, extracts it via shell tar, installs its npm dependencies, and executes arbitrary code from the extracted peer-math.js module. The attacker controls the Vercel-hosted config endpoint, enabling arbitrary remote code execution on every install.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 01:02 PM
analyzed
Jul 17, 2026, 01:04 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.