{
  "schema_version": "1.6.0",
  "id": "MAL-2026-11499",
  "modified": "2026-07-29T18:00:00Z",
  "published": "2026-07-29T18:00:00Z",
  "summary": "@types-beta/sdk — an import-time Windows RAT hiding behind the @types namespace",
  "details": "A malicious npm package that impersonates the trusted @types TypeScript-definitions scope. Simply importing it launches a bundled Windows remote-access agent — no install script, no user action.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "@types-beta/sdk"
      },
      "versions": [
        "0.1.3"
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3041-types-beta-sdk"
    },
    {
      "type": "ADVISORY",
      "url": "https://osv.dev/vulnerability/MAL-2026-11499"
    }
  ],
  "credits": [
    {
      "name": "Sascha Klein, codelake Research",
      "type": "FINDER",
      "contact": [
        "https://research.codelake.dev"
      ]
    }
  ],
  "database_specific": {
    "caseId": "CLR-2026-3041",
    "kind": "malware",
    "class": "Native-binary dropper → Windows RAT",
    "severity": "Critical",
    "status": "Reported",
    "iocs": {
      "ips": [],
      "hashes": [
        "sha256:9c7aaf7078a0e0de15a4855e541946b0952a024e84735f1ad39b0b91ad257851",
        "sha256:b2e985dfc5a494c8bd2f6e2e7a22d35cc0964c0103a596de62e150c2df8097e2"
      ],
      "indicators": [
        "npm: @types-beta/sdk — versions 0.1.0, 0.1.1, 0.1.2, 0.1.3 (live)",
        "Bundled binary: vendor/nanocache.exe (Windows PE) — sha256 9c7aaf7078a0e0de15a4855e541946b0952a024e84735f1ad39b0b91ad257851",
        "Tarball sha256 (0.1.3): b2e985dfc5a494c8bd2f6e2e7a22d35cc0964c0103a596de62e150c2df8097e2",
        "Trigger: import-time side effect (dist/index.js → init()), Windows only",
        "C2: outbound WinHTTP WebSocket, remote command exec + interactive PowerShell, auto-reconnect"
      ]
    }
  }
}