typescipt-core 1.0.0
Malicious postinstall downloads and executes payload
Install hook XOR-decodes then POSTs /vote beaconPlaceholder-module package runs an install hook
SHA-2564d006a7286c06e0ace84aae9b91cab12783f7cc00cab2ecda8ee3726ae9af282
Also flagged by osv (MAL-2026-14147: Malicious code in typescipt-core (npm)) +2 more.