LWA-2026-12366 MAL-2026-17157 ↗ confirmed malware

eslint-config-compact-base@1.0.0

Malicious code in eslint-config-compact-base (npm)

T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

eslint-config-compact-base@1.0.0 is an ESLint config package whose main module (index.js) silently beacons host metadata to a remote endpoint whenever it is required. On load it collects the machine's hostname, username, platform, architecture, Node version, current working directory, and the CI / RUNNER_NAME / GITHUB_REPOSITORY environment variables, URL-encodes them, and sends them via HTTPS GET to hxxps://cbrsuo9293[.]execute-api[.]us-east-1[.]amazonaws[.]com/c. This data exfiltration is unrelated to the package's stated purpose of providing ESLint rules.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 02:15 PM
analyzed
Sep 23, 2026, 02:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.