eslint-plugin-mistica-local-rules@19.12.11
Malicious code in eslint-plugin-mistica-local-rules (npm)
Analysis
Combosquats the real eslint-plugin-mistica design-system plugin at an inflated version. Its preinstall hook runs index.js, which collects detailed system information (hostname, platform, arch, user info including uid/gid/shell, OS type/release/memory/CPU count, whoami, id output, cwd) and POSTs it as JSON to eucfugc8bk66haszliir75yd74dv1lpa[.]oastify[.]com/detox56. A bundled file package/i contains harvested Instagram follower data (names, usernames, timestamps). The host-fingerprinting beacon to an out-of-band exfil endpoint is clear reconnaissance malware.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 06:40 PM
- analyzed
- Jun 12, 2026, 06:40 PM
Related advisories
- qr-code-styling-temp@9.9.10
- atlassian-forge-skills@29.1.0
- pumpdotfun-sdk-v3.0@3.1.3
- pt-logger-telemetry-eax0x1@1.0.0
- protectstraizolib@1.0.8
- program-commander@14.1.9
- pretty-pino-logger@2.0.2
- pretty-fancy@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.