LWA-2026-11779 MAL-2026-15601 ↗ confirmed malware

eslint-prettier-js@0.0.1

Malicious code in eslint-prettier-js (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook (scripts/postinstall.cjs) runs on install and calls a function in index.cjs that fetches hxxps://2939e69fc408[.]ngrok-free[.]app/stats and executes the returned content with eval(), giving the remote server arbitrary code execution on the installer's machine at install time. The package is a minimal stub with no actual eslint/prettier functionality.

analyzed by
Leitwacht
first seen
Aug 31, 2026, 02:39 AM
analyzed
Aug 31, 2026, 02:39 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.