MAL-2026-14149
Malicious code in typescirpt-core (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ef20a464d9f616eecfd6457a02895da80d1fabf558ef49de83dca18046551e90) Package name 'typescirpt-core' typosquats 'typescript'. scripts/postinstall.js runs automatically on npm install and posts a JSON platform beacon to a hardcoded bare-IP endpoint at http://193.70.34.101:20099/vote (host constructed by array-join to evade static matching). It then XOR-decodes (key 'stf2026') an embedded integer array into a remote URL and downloads a Windows executable to %TEMP%/main.exe, spawning it detached with stdio ignored and window hidden. A separate WSL-detection branch XOR-decodes a PowerShell bridge launcher and pre/post script fragments and passes the reconstructed command to child_process.exec, so a Linux WSL install pivots execution back to the host Windows side. The URL, launcher command, and script fragments are all stored as XOR-encoded byte arrays and reconstructed at runtime immediately before exec/https.get, hiding the download destination and command line from static inspection.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for typescirpt-core (npm). Pin to a known-safe version or switch to an alternative.