ts-eslint-helper@4.0.1
Malicious code in ts-eslint-helper (npm)
Analysis
ts-eslint-helper@4.0.1 is a credential stealer disguised as a helper tool. index.js uses base64-obfuscated string constants and recursively scans the current working directory for sensitive files (id.json Solana/Phantom wallets; config.toml/Config.toml; config.json; .env/env; and Solana seed-phrase markers), prepends USER@localIP to each, and POSTs the contents via axios to hxxps://cloudflare-prevention[.]vercel[.]app/api/v1 with attachment headers. test.js (run via `npm test`) auto-triggers full exfiltration. There is no lifecycle hook, so execution requires explicit require/run, but the code is unambiguously built to harvest crypto wallet keys, config secrets, and environment credentials.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:15 AM
- analyzed
- Jun 11, 2026, 09:18 AM
Related advisories
- ts-ecro@0.0.6
- mw-filesystem-events-nodream_compat@99.99.99
- mw-filesystem-events-nodream@0.0.32
- solana-core-4@1.0.0
- ethereum-kit-1@1.0.0
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.