MAL-2026-14148

    Dashboard / Malicious Package / MAL-2026-14148

    MAL-2026-14148

    Published: 18 Aug 2026Last Modified: 18 Aug 2026

    Summary: Malicious code in typescirpt-cli (npm)

    Details: Source: amazon-inspector (09d82fa51e42e6766fe0819517e9fb5be633702a0e22cb4da05d8920cb413c53) The package's postinstall script (scripts/postinstall.js) XOR-decodes obfuscated byte arrays using the key 'stf2026' to reconstruct a download URL and a powershell command. On Windows, and on Linux when WSL is detected, it downloads an opaque main.exe from https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe (an unrelated personal GitHub account, no version tag, no hash/signature verification) into TEMP and spawns it detached; from WSL it invokes a decoded powershell.exe bridge to fetch and run the binary on the Windows host. Separately, sendInstallMetrics POSTs a JSON payload containing node/arch/platform to the hardcoded bare IP 193.70.34.101:20099/vote over plain HTTP, with the host reconstructed via array-join to obscure the literal. The package name typosquats 'typescript-cli'.

    Affected packages

    Package

    Name: typescirpt-cli

    Purl: pkg:npm/typescirpt-cli

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0