eslint-prettier-js@0.0.1
Malicious code in eslint-prettier-js (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook (scripts/postinstall.cjs) runs on install and calls a function in index.cjs that fetches hxxps://2939e69fc408[.]ngrok-free[.]app/stats and executes the returned content with eval(), giving the remote server arbitrary code execution on the installer's machine at install time. The package is a minimal stub with no actual eslint/prettier functionality.
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 02:39 AM
- analyzed
- Aug 31, 2026, 02:39 AM
Related advisories
- originaldevelopmentstelemetry@1.2.2
- developmentstelemetry@1.0.1
- node-request-utils@1.0.0
- mfaatest@1.0.0
- mfafix@1.0.0
- cbc97b7a@1.1787999998.0
- exprss-helmet@1.0.1
- grafeno-payments@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.