mjs-eslint-service@7.0.5
Malicious code in mjs-eslint-service (npm)
Analysis
mjs-eslint-service@7.0.5 is a trojanized clone of the big.js decimal arithmetic library from a malicious publisher. The package copies big.js's description, repository URL, and author identity to appear legitimate, but contains injected code in both big.js and big.mjs that loads and executes a known-malicious dependency (require('ts-eslint-helper').from_str()). The package also declares a dependency on mjs-eslint-helper, another known-malicious package. When the library is imported at runtime, the injected loader activates the malware dependency, executing its payload on the installer's system.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 06:03 PM
- analyzed
- Jun 18, 2026, 06:06 PM
Related advisories
- mjs-eslint-helper@4.0.1
- env-config-f281@1.0.0
- panrouter@5.0.0
- panrouter-admin@5.0.0
- metavu@99.21.1-1.21.127
- computerrock-babel-preset-react-app@15.12.11
- chai-as-attested@6.0.3
- @zynkit/jwtbytes@0.5.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.