Hostile 100% javascript Download

typescipt-core 1.0.0

Malicious postinstall downloads and executes payload

Install hook XOR-decodes then POSTs /vote beaconPlaceholder-module package runs an install hook

Also flagged by osv (MAL-2026-14147: Malicious code in typescipt-core (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.