LWA-2026-11811 confirmed malware
eslint-rxjs@1.0.0
Malicious code in eslint-rxjs (npm)
T1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
The package's postinstall hook executes a function that makes an HTTP request to an ngrok tunnel endpoint (hxxps://e493-95-216-46-122[.]ngrok-free[.]app/ping) on every install, beaconing to an attacker-controlled tunnel to confirm the package was installed. The package name combines two popular packages (eslint, rxjs) and its metadata is unrelated to its actual function.
- analyzed by
- Leitwacht
- first seen
- Sep 1, 2026, 04:23 AM
- analyzed
- Sep 1, 2026, 04:23 AM
Related advisories
- chromatitle@1.0.0
- tailwindcss-forms-style@0.1.2
- @divineubg/divine@1.1.2
- tailwind-minanimated@2.3.7
- tailwind-modernanimation@2.3.8
- hectorstatic@1.0.1
- telegramxjm@1.0.1
- fuels-versions@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.