VDB
EN

MAL-2026-14157

Malicious code in typscript-core (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5120bfde64344d0e161bac3b4128d7eeecc483ad796361db09eacd138ecd3945) typscript-core is a typosquat of the 'typescript' package. Its scripts/postinstall.js reconstructs a GitHub download URL and shell commands from byte arrays XOR-decoded with the key 'stf2026', downloads a binary to %TEMP%\main.exe, and spawns it detached with windowsHide:true on win32 (and via a PowerShell bridge on WSL). The same postinstall also POSTs platform information to a hardcoded bare-IP endpoint at http://193.70.34.101:20099/vote, with the IP assembled from a four-element string array to evade static search. The URLs, shell commands, and destination IP are all obfuscated and reconstructed at runtime.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / typscript-core

No fixed version published yet for typscript-core (npm). Pin to a known-safe version or switch to an alternative.

참고