ts-eslinter@1.0.0
Malicious code in ts-eslinter (npm)
Analysis
Package ts-eslinter@1.0.0 is a typosquat targeting eslint/typescript-eslint. Its main module (index.js) uses base64-obfuscated strings to conceal credential-theft behaviour: on import (or when the test script is executed), it recursively searches the working directory for Solana/Phantom wallet key files (id.json), configuration files (config.json, config.toml), and environment files (.env, env). Each found file is read, prepended with the system's USER environment variable and local IP address, and exfiltrated via HTTP POST to parker-server-help[.]vercel[.]app/api/v1 as an octet-stream attachment. IOCs: hxxps://parker-server-help[.]vercel[.]app/api/v1 — host: parker-server-help[.]vercel[.]app, path: /api/v1.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 01:47 PM
- analyzed
- Jun 19, 2026, 01:47 PM
Related advisories
- new-ts-helper@9.0.2
- new-helper@5.8.1
- ts-big-ecro@3.8.1
- stitch-design@0.1.0
- log-taker@0.0.7
- new-solt-1@0.0.9
- new-solt@0.0.7
- node-slot@1.0.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.