MAL-2026-14149
Dashboard / Malicious Package / MAL-2026-14149
MAL-2026-14149
Summary: Malicious code in typescirpt-core (npm)
Details: Source: amazon-inspector (ef20a464d9f616eecfd6457a02895da80d1fabf558ef49de83dca18046551e90) Package name 'typescirpt-core' typosquats 'typescript'. scripts/postinstall.js runs automatically on npm install and posts a JSON platform beacon to a hardcoded bare-IP endpoint at http://193.70.34.101:20099/vote (host constructed by array-join to evade static matching). It then XOR-decodes (key 'stf2026') an embedded integer array into a remote URL and downloads a Windows executable to %TEMP%/main.exe, spawning it detached with stdio ignored and window hidden. A separate WSL-detection branch XOR-decodes a PowerShell bridge launcher and pre/post script fragments and passes the reconstructed command to child_process.exec, so a Linux WSL install pivots execution back to the host Windows side. The URL, launcher command, and script fragments are all stored as XOR-encoded byte arrays and reconstructed at runtime immediately before exec/https.get, hiding the download destination and command line from static inspection.
Affected packages
Package
Name: typescirpt-core
Purl: pkg:npm/typescirpt-core
Affected ranges
Type: N/A
Events:
