Logo
npm

@types-beta/sdk@0.1.3

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC

Malicious

OSV ID

MAL-2026-11499

Ecosystem

npm

Summary

The package masquerades as a type-definitions package in the @types-beta/* namespace but ships a 1.1 MB Windows executable at vendor/nanocache.exe. The main entry dist/index.js calls init() at module load time, which on Windows spawns vendor/nanocache.exe with detached: true, stdio: "ignore", windowsHide: true, then child.unref()s it, so a hidden background process starts whenever a consumer writes import "@types-beta/sdk". The bundled PE (sha256 9a65f46787db4dd1e278a06f617094c59ca113ee92f6a8021b62967bb64b947a) contains embedded strings consistent with a remote-control agent (/ws/agent, disconnect, update, exit_code). The README reinforces the impersonation by contrasting the package with @types-beta/node as "type definitions only", while this package auto-executes native code on import. Import-time launch of an opaque, undocumented native binary with agent-shaped protocol strings on a namespace crafted to imitate DefinitelyTyped constitutes a backdoor installation on the developer's host.

Source: amazon-inspector (5a3bdb989bdab8b3038c0eb791bf3e09ee753c363d198162f54420b82d9326ed)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.