-= Per source details. Do not edit below this line.=-
tyepescript-cli is a typosquat of typescript. Its scripts/postinstall.js XOR-decodes (key stf2026) a set of obfuscated byte arrays that resolve to an attacker-controlled URL, a PowerShell bridge command, and script fragments. On Windows, the postinstall downloads main.exe from github.com/bebrazi/qPbM50V1AKG0rVlH/releases/download/null/main.exe to %TEMP%\main.exe and spawns it detached. Under WSL, it decodes a powershell.exe bridge command and execs it via child_process.exec with windowsHide: true to fetch and run the same binary on the Windows host from the Linux install context. Before the drop, the script POSTs a JSON body with a host label to a hardcoded numeric IP http://193.70.34.101:20099/vote (host built by joining the array ['193','70','34','101'] to hide the literal) as an install-time beacon. The mutable releases/download/null/ path on an anonymous personal GitHub account (bebrazi) is unrelated to any legitimate typescript publisher, and the XOR obfuscation of URLs and commands has no benign purpose in an npm install script.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-18T23:41:21.450977689Z",
"sha256": "8a867a5fc578cb6dcb759370e837d1a4c7e24f6db63c0c0f781e2c24995905e6",
"modified_time": "2026-08-18T23:19:37Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018180",
"versions": [
"1.0.0"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tyepescript-cli/MAL-2026-14143.json"
{
"evidence_files": [
{
"sha256": "b411176fb75b99b3fbf80915fca95ad643d567117e86e3a99813cb0958a1181f",
"path": "scripts/postinstall.js",
"tlsh": "2bd13fca1ef59035874bf96884cf9d13b2a6c207320d4a65ff8f42107f5793c85a69e9"
}
],
"package_integrity": [
{
"filename": "tyepescript-cli-1.0.0.tgz",
"hashes": {
"sha1": "a9331be045034272dedb7fa3fd051dd1b006dbda",
"sha512_sri": "sha512-7K3/w3Qok3uyL6XzINa4NLHPa5F5V/EFGpMJkzL/h41STsSshUTlQ3G/Dx+LPjgrCtpmtJQjgDrOFY6JP4N3FA=="
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]