MAL-2026-14148
Malicious code in typescirpt-cli (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (09d82fa51e42e6766fe0819517e9fb5be633702a0e22cb4da05d8920cb413c53) The package's postinstall script (scripts/postinstall.js) XOR-decodes obfuscated byte arrays using the key 'stf2026' to reconstruct a download URL and a powershell command. On Windows, and on Linux when WSL is detected, it downloads an opaque main.exe from https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe (an unrelated personal GitHub account, no version tag, no hash/signature verification) into TEMP and spawns it detached; from WSL it invokes a decoded powershell.exe bridge to fetch and run the binary on the Windows host. Separately, sendInstallMetrics POSTs a JSON payload containing node/arch/platform to the hardcoded bare IP 193.70.34.101:20099/vote over plain HTTP, with the host reconstructed via array-join to obscure the literal. The package name typosquats 'typescript-cli'.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for typescirpt-cli (npm). Pin to a known-safe version or switch to an alternative.