LWA-2026-6210 MAL-2026-10087 ↗ confirmed malware

eslint-plus@6.0.4

Malicious code in eslint-plus (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

eslint-plus is a combosquat package impersonating the eslint linter. On install, the postinstall hook runs a script that spawns a detached background Node.js process. This process fetches attacker-controlled code from hxxps://jsonkeeper[.]com/b/UTUUE and executes it via new Function, enabling arbitrary remote code execution on the installer's machine. The package ships a trojanized copy of the nodemailer library as its payload cover.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 01:04 PM
analyzed
Jul 1, 2026, 08:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.