eslint-jest@4.0.5
Malicious code in eslint-jest (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The postinstall script (scripts/install-check.cjs) fetches a JSON config from hxxps://trabalhos-flax[.]vercel[.]app/config/clob-math[.]json, resolves a .tgz bundle URL from that config, downloads the tarball, extracts it with shell tar, runs npm install inside the extracted directory, then requires and executes peer-math.js from the bundle. This is a multi-stage remote code execution dropper — the second-stage payload is fully attacker-controlled.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 08:51 AM
- analyzed
- Jul 2, 2026, 08:54 AM
Related advisories
- eslint-jest@4.0.6 same package
- chain-chai-await@1.3.5
- svgson-lite@1.0.4
- svgcraft-core@1.0.1
- notify-theme@1.3.5
- chain-chai-async@1.3.5
- notifier-log@1.3.5
- eslint-plus@6.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.