eslint-helper@4.0.1
Malicious code in eslint-helper (npm)
Analysis
This package is a credential and information stealer disguised as an ESLint helper. When invoked, it recursively scans the working directory for files named id.json (crypto wallet keys), .env and env (environment secrets), config.json, and config.toml, and reads bash, zsh, fish, sh, and PowerShell command history files. All collected data is exfiltrated via HTTP POST to hxxps://vercel-backend-rn1xzfaz~djbdhdfjjtj5-2167s-projects[.]vercel[.]app/api/v1 with Content-Type: application/octet-stream and the victim's USER env variable and local IP address as metadata prefix. The package name "eslint-helper" combosquats the ESLint tool to trick developers into installing it.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 07:18 PM
- analyzed
- Jun 18, 2026, 07:19 PM
Related advisories
- parket-helper@0.0.1
- log-taker1@0.1.0
- eslint-helper-1@5.0.4
- node-slot@1.0.7
- node-vfs-polyfill@2.0.5
- mjs-eslint-helper@4.0.1
- server-parket@3.8.1
- env-config-f281@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.