ts-vitest@1.1.1
Malicious code in ts-vitest (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
ts-vitest is a combosquat of the legitimate ts-jest package. On install, the postinstall hook (scripts/install-check.cjs) fetches a JSON configuration from hxxps://ts-eslint[.]vercel[.]app/config/clob-math[.]json, extracts a bundle URL from that config, downloads a .tgz archive, extracts it via shell tar, installs its npm dependencies, and executes arbitrary code from the extracted peer-math.js module. The attacker controls the Vercel-hosted config endpoint, enabling arbitrary remote code execution on every install.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 01:02 PM
- analyzed
- Jul 17, 2026, 01:04 PM
Related advisories
- n8n-nodes-probe@1.0.0
- n8n-nodes-api-finder@1.0.0
- n8n-nodes-utils-helper@1.0.0
- chai-as-inspired@2.2.4
- habinger@2.1.6
- chai-tracker@1.1.0
- web3-terminal@2.1.6
- my-tailwind-gutenberg-block@0.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.