LWA-2026-5769 MAL-2026-6896 ↗ confirmed malware

ts-eslinter@1.0.0

Malicious code in ts-eslinter (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Package ts-eslinter@1.0.0 is a typosquat targeting eslint/typescript-eslint. Its main module (index.js) uses base64-obfuscated strings to conceal credential-theft behaviour: on import (or when the test script is executed), it recursively searches the working directory for Solana/Phantom wallet key files (id.json), configuration files (config.json, config.toml), and environment files (.env, env). Each found file is read, prepended with the system's USER environment variable and local IP address, and exfiltrated via HTTP POST to parker-server-help[.]vercel[.]app/api/v1 as an octet-stream attachment. IOCs: hxxps://parker-server-help[.]vercel[.]app/api/v1 — host: parker-server-help[.]vercel[.]app, path: /api/v1.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 01:47 PM
analyzed
Jun 19, 2026, 01:47 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.