`ts-einkle` + `ts-ankle` + `ts-einkle-slot` - crypto-wallet drainer / SSH backdoor / big.js typosquat cluster
Between 2026-06-26 and 2026-06-27 a single naming-cluster operator published three new malicious npm packages - ts-einkle (5 versions), ts-einkle-slot (5 versions), and ts-ankle (1 version). All three execute install-time payloads: ts-einkle is a full credential and crypto-wallet stealer exfiltrating to datasecure-service.vercel.app/api/v1; ts-ankle recursively walks the home directory for credential files and installs an SSH public key in ~/.ssh/authorized_keys; ts-einkle-slot typosquats big.js and shadow-loads node-slot on every require(). npm-support replaced all three with 0.0.1-security holders on 2026-06-29.
Versions named here: 1.0.9, 1.1.0, 1.1.2, 1.1.3