LWA-2026-7020 MAL-2026-12812 ↗ confirmed malware

ts-toolkit-plus@1.3.2

Malicious code in ts-toolkit-plus (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information Discovery

Analysis

ts-toolkit-plus@1.3.2 is a combosquat of the legitimate ts-toolkit package. When imported, index.js fetches a remote payload from hxxps://31[.]97[.]137[.]157:45000/icons/112 (with custom header bearrtoken: logo) and executes the response's data.credits field via new Function() with full Node.js runtime access (require, process, Buffer, module, exports). The package includes node-machine-id for host fingerprinting and retries the fetch up to 3 times on failure. The README is a generic template that does not describe the actual code.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 10:31 AM
analyzed
Jul 22, 2026, 10:32 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.