Malicious code in typst-resume-cli (npm)
Malicious code was discovered in the npm package typst-resume-cli. The compromised package exfiltrates environment variables and host attributes to an attacker-controlled AWS Lambda endpoint.
- Disclosed
- Last updated
- Blast radius
- All npm users who installed affected versions of typst-resume-cli
- Ecosystems
- Attack vectors
- Affected entities
- typst-resume-clinpm package
The npm package typst-resume-cli contained malicious code that loads the https, http, and child_process modules at the top of index.js. The code collects sensitive host and environment data, including process.env variables and platform information, and sends this credential-grade content to an attacker-controlled AWS Lambda URL at https://oo7fsr4cy32q42bzkpgwhy7asu0hzaod.lambda-url.us-east-1.on.aws.\n\nThe malicious endpoint is unrelated to any legitimate Typst or resume tooling publisher, indicating a compromised package rather than a typosquatting attack. The exfiltration occurs conditionally based on the host platform, suggesting targeted data collection.\n\nThe incident was identified through Amazon Inspector and reported by the OpenSSF malicious packages project. The package has been flagged in the npm advisory system (GHSA-h5p6-64p5-63vm).
Indicators of compromise
- Packages
- typst-resume-cli
- Domains
- oo7fsr4cy32q42bzkpgwhy7asu0hzaod.lambda-url.us-east-1.on.aws
Remediation
- Immediately uninstall typst-resume-cli from all systems
- Audit environment variables and secrets that may have been exposed during the package installation
- Review AWS Lambda logs and network traffic to the attacker-controlled endpoint for evidence of data exfiltration
- Rotate any credentials or sensitive data that may have been present in environment variables at the time of installation
- Check npm audit logs and package.json for any unexpected dependencies or versions of typst-resume-cli
Sources
- GitHub Advisory GHSA-h5p6-64p5-63vm · GitHub Advisory Database
Cite this entry
"Malicious code in typst-resume-cli (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 6, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-typst-resume-cli-npm-pd7iob
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit - containedcritical
Malicious code in checkout-desktop-total (npm)
The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.
npmCompromised package - containedcritical
Malicious code in epic-common (npm)
The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malware in @siwatfa/yorn
Malware was discovered in the npm package @siwatfa/yorn. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package