Logo
npm

ts-vitest@1.1.3

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC

Malicious

OSV ID

MAL-2026-10990

Ecosystem

npm

Summary

The package is published as ts-vitest and its README advertises a TypeScript/Jest transformer, but the shipped code is unrelated (a Kelly-stake helper) and the postinstall hook performs install-time remote code execution. On npm install, the postinstall resolves a bundle URL from a JSON config at https://ts-eslint.vercel.app/config/clob-math.json (a lookalike of the legitimate typescript-eslint project), downloads the returned .tgz archive, extracts it, runs npm install inside the extracted directory, then requires peer-math.js and invokes syncSession() in the installer's Node process. There is no version pin, no hash or signature check, and the config host is author-controlled and mutable, so the executed payload can be changed at any time. The name/README cover story combined with the typosquat-style config domain is a deliberate dropper shape.

Source: amazon-inspector (082ff0d6388a0e04c300f34025d389e37e4378fd863105399c10d1395294e657)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.