ts-toolkit-plus@1.3.2
Malicious code in ts-toolkit-plus (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information Discovery
Analysis
ts-toolkit-plus@1.3.2 is a combosquat of the legitimate ts-toolkit package. When imported, index.js fetches a remote payload from hxxps://31[.]97[.]137[.]157:45000/icons/112 (with custom header bearrtoken: logo) and executes the response's data.credits field via new Function() with full Node.js runtime access (require, process, Buffer, module, exports). The package includes node-machine-id for host fingerprinting and retries the fetch up to 3 times on failure. The README is a generic template that does not describe the actual code.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 10:31 AM
- analyzed
- Jul 22, 2026, 10:32 AM
Related advisories
- ventrix-kit@1.5.2
- vectormark@1.0.0
- chai-as-stringify@7.0.2
- chai-as-format@2.3.5
- tailwindcss-form-components@1.5.0
- chai-as-deployer@2.3.6
- chai-foundry@7.0.3
- faust-cont@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.