LWA-2026-11811 confirmed malware

eslint-rxjs@1.0.0

Malicious code in eslint-rxjs (npm)

T1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

The package's postinstall hook executes a function that makes an HTTP request to an ngrok tunnel endpoint (hxxps://e493-95-216-46-122[.]ngrok-free[.]app/ping) on every install, beaconing to an attacker-controlled tunnel to confirm the package was installed. The package name combines two popular packages (eslint, rxjs) and its metadata is unrelated to its actual function.

analyzed by
Leitwacht
first seen
Sep 1, 2026, 04:23 AM
analyzed
Sep 1, 2026, 04:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.