LWA-2026-5739 MAL-2026-6187 ↗ confirmed malware

eslint-helper@4.0.1

Malicious code in eslint-helper (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.003 · Bash HistoryT1041 · Exfiltration Over C2 Channel

Analysis

This package is a credential and information stealer disguised as an ESLint helper. When invoked, it recursively scans the working directory for files named id.json (crypto wallet keys), .env and env (environment secrets), config.json, and config.toml, and reads bash, zsh, fish, sh, and PowerShell command history files. All collected data is exfiltrated via HTTP POST to hxxps://vercel-backend-rn1xzfaz~djbdhdfjjtj5-2167s-projects[.]vercel[.]app/api/v1 with Content-Type: application/octet-stream and the victim's USER env variable and local IP address as metadata prefix. The package name "eslint-helper" combosquats the ESLint tool to trick developers into installing it.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 07:18 PM
analyzed
Jun 18, 2026, 07:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.