LWA-2026-7200 MAL-2026-11499 ↗ confirmed malware

@types-beta/sdk@0.1.3

Malicious code in @types-beta/sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.003 · Windows Command ShellT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1113 · Screen CaptureT1041 · Exfiltration Over C2 ChannelT1082 · System Information Discovery

Analysis

@types-beta/sdk@0.1.3 is a combosquat package impersonating the @types/beta scope. When imported at application startup, dist/init.js spawns vendor/nanocache.exe as a hidden, detached Windows process. The bundled PE binary is a "Screen Monitor Agent" RAT that connects via WebSocket to wss://nanocache-optimizer[.]onrender[.]com/ws/agent, captures screen content via GDI+, executes remote commands, and enforces a singleton mutex (Local\ScreenMonitorAgentMutex). The C2 server is nanocache-optimizer[.]onrender[.]com on port 443 (WebSocket secure). The package has no repository and no legitimate purpose.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 09:09 PM
analyzed
Jul 28, 2026, 09:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.