MAL-2026-14152

    Dashboard / Malicious Package / MAL-2026-14152

    MAL-2026-14152

    Published: 18 Aug 2026Last Modified: 18 Aug 2026

    Summary: Malicious code in typescriptt-core (npm)

    Details: Source: amazon-inspector (b701541fd1cac460b8ab9a3e24dd1d0e476965e4d247826f5108e4a8eb6996d8) typescriptt-core is a typosquat of the TypeScript ecosystem (double-t) with an empty main (module.exports = {}) and no library functionality. The only code that runs is scripts/postinstall.js, which XOR-decodes a hidden URL and PowerShell launcher using the fixed key 'stf2026' and, on Windows, downloads main.exe from https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe to %TEMP% and spawns it detached. On WSL, the same script decodes a bridge command and invokes powershell.exe on the Windows host to perform the same fetch-and-run. Before the drop, postinstall POSTs a small JSON payload containing the host platform label to a hardcoded bare-IP endpoint http://193.70.34.101:20099/vote over plain HTTP as an install beacon. The destination GitHub account (bebraz1) is unrelated to the TypeScript project, the payload is opaque, and both the URL and the PowerShell command are XOR-obfuscated to defeat static review.

    Affected packages

    Package

    Name: typescriptt-core

    Purl: pkg:npm/typescriptt-core

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0