eslint-config-compact-base@1.0.0
Malicious code in eslint-config-compact-base (npm)
Analysis
eslint-config-compact-base@1.0.0 is an ESLint config package whose main module (index.js) silently beacons host metadata to a remote endpoint whenever it is required. On load it collects the machine's hostname, username, platform, architecture, Node version, current working directory, and the CI / RUNNER_NAME / GITHUB_REPOSITORY environment variables, URL-encodes them, and sends them via HTTPS GET to hxxps://cbrsuo9293[.]execute-api[.]us-east-1[.]amazonaws[.]com/c. This data exfiltration is unrelated to the package's stated purpose of providing ESLint rules.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 02:15 PM
- analyzed
- Sep 23, 2026, 02:16 PM
Related advisories
- @memtensor/memos-cloud-openclaw-plugin@0.1.23
- efhthrthrthregerht@99.9.9
- faceplate-docs@99.9.9
- eslint-plugin-i18n-shreddit@99.9.9
- @tvg-mar/utils@9.9.10
- @tvg-mar/promos-gtm@9.9.10
- @tvg-mar/promos-context@9.9.10
- @tesla-insurance/vinless-quote@9.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.