MAL-2026-10990
Malicious code in ts-vitest (npm)
상세
ts-vitest is a typosquat of vitest/ts-eslint (hollow "kelly-calc"/"clob-math" content, no legitimate functionality) that ships a postinstall two-stage fetch-exec dropper. The package.json declares `postinstall: node scripts/install-check.cjs`; the hook's `resolvePeerBundleUrl()` fetches a JSON config from a hardcoded, typosquatting host (`https://ts-eslint.vercel.app/config/clob-math.json`, also the package.json homepage), reads a second-stage tarball URL out of that config, npm installs the tarball, then `require()`s and executes it — achieving install-time RCE before any package code is used. The config JSON resolves to a second-stage tarball at `https://ts-eslint.vercel.app/releases/psm-peer.tgz`, whose `main` entry point is `peer-math.js`. The config indirection (an ephemeral *.vercel.app host serving JSON that points at the real payload) keeps the tarball URL out of the package bytes, defeating a naive grep for a hardcoded payload URL.
The lineage alternates malicious and clean releases: 1.1.1 shipped the dropper (previously convicted), 1.1.2 removed the postinstall hook as a clean decoy, and 1.1.3 restores a byte-identical copy of the 1.1.1 dropper. The hook is entirely YARA-invisible (0 matches); detection required reading the hook's logic directly rather than relying on signature scoring. Published by sole npm maintainer `naradi` (maintainer email `les.t.e.rbigs.antos@gmail.com`), who pushed 7 versions in ~6.5 hours.
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (082ff0d6388a0e04c300f34025d389e37e4378fd863105399c10d1395294e657) The package is published as `ts-vitest` and its README advertises a TypeScript/Jest transformer, but the shipped code is unrelated (a Kelly-stake helper) and the postinstall hook performs install-time remote code execution. On `npm install`, the postinstall resolves a bundle URL from a JSON config at `https://ts-eslint.vercel.app/config/clob-math.json` (a lookalike of the legitimate `typescript-eslint` project), downloads the returned `.tgz` archive, extracts it, runs `npm install` inside the extracted directory, then `require`s `peer-math.js` and invokes `syncSession()` in the installer's Node process. There is no version pin, no hash or signature check, and the config host is author-controlled and mutable, so the executed payload can be changed at any time. The name/README cover story combined with the typosquat-style config domain is a deliberate dropper shape.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
0 No fixed version published yet for ts-vitest (npm). Pin to a known-safe version or switch to an alternative.