MAL-2026-14157
Malicious code in typscript-core (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5120bfde64344d0e161bac3b4128d7eeecc483ad796361db09eacd138ecd3945) typscript-core is a typosquat of the 'typescript' package. Its scripts/postinstall.js reconstructs a GitHub download URL and shell commands from byte arrays XOR-decoded with the key 'stf2026', downloads a binary to %TEMP%\main.exe, and spawns it detached with windowsHide:true on win32 (and via a PowerShell bridge on WSL). The same postinstall also POSTs platform information to a hardcoded bare-IP endpoint at http://193.70.34.101:20099/vote, with the IP assembled from a four-element string array to evade static search. The URLs, shell commands, and destination IP are all obfuscated and reconstructed at runtime.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for typscript-core (npm). Pin to a known-safe version or switch to an alternative.