LWA-2026-5735 MAL-2026-6333 ↗ confirmed malware

mjs-eslint-service@7.0.5

Malicious code in mjs-eslint-service (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

mjs-eslint-service@7.0.5 is a trojanized clone of the big.js decimal arithmetic library from a malicious publisher. The package copies big.js's description, repository URL, and author identity to appear legitimate, but contains injected code in both big.js and big.mjs that loads and executes a known-malicious dependency (require('ts-eslint-helper').from_str()). The package also declares a dependency on mjs-eslint-helper, another known-malicious package. When the library is imported at runtime, the injected loader activates the malware dependency, executing its payload on the installer's system.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 06:03 PM
analyzed
Jun 18, 2026, 06:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.