MAL-2026-14147
Malicious code in typescipt-core (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (98b97af3a328b837904c7860b7acbae33bea28afb53949905868867905c14be6) Package name typosquats `typescript`. The postinstall script (scripts/postinstall.js) XOR-decodes a download URL and a PowerShell launcher using key 'stf2026', then on Windows fetches an executable to %TEMP%\main.exe and spawns it detached; on WSL it decodes and executes a PowerShell bridge via exec. Before fetching the second stage, it POSTs a host-profile JSON (including a Windows/WSL label derived from inspecting /proc/version and /proc/sys/kernel/osrelease) over plain HTTP to the hardcoded bare IP 193.70.34.101 on port 20099 at path /vote. The network destinations and shell command are stored as XOR-encoded byte arrays (ADDON_ENC, BRIDGE_LAUNCHER_ENC, BRIDGE_SCRIPT_PRE_ENC, BRIDGE_SCRIPT_POST_ENC) and reconstructed at runtime. Cover-story identifiers ('TELEMETRY', 'addon') mask an install-time dropper: `npm install typescipt-core` results in attacker-controlled code executing on the installer's host.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for typescipt-core (npm). Pin to a known-safe version or switch to an alternative.