tick-forge@11.5.2
Malicious code in tick-forge (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
tick-forge@11.5.2 is a combosquat of the legitimate tickforge package. On import, it fetches a remote payload from 31[.]97[.]137[.]157:45000/icons/107 over HTTPS and executes the response via new Function() with full Node.js globals (require, process, Buffer), enabling arbitrary remote code execution. The README describes a fake trading toolkit that does not match the actual behaviour.
- analyzed by
- Leitwacht
- first seen
- Jul 23, 2026, 01:32 PM
- analyzed
- Jul 23, 2026, 01:33 PM
Related advisories
- ambera@1.0.0
- gekko-trading-bot@4.2.0
- fastify-client-bundler@1.4.0
- react-tabulix-ui@0.1.2
- encryptstringadmin@1.2.1
- poly-provider-api@4.6.1
- async-mutex-lock@5.3.1
- dbconnectify@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.