LWA-2026-6240 confirmed malware

mjs-eslint@7.0.7

Malicious code in mjs-eslint (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

mjs-eslint@7.0.7 is a trojanized clone of the legitimate big.js library. It copies the entire big.js source tree verbatim but injects a require('ts-eslint-helper') call at line 605 of both big.js and big.mjs that executes at module evaluation time. The ts-eslint-helper dependency recursively searches the current working directory for credential and configuration files (id.json, config.toml, config.json, .env, env) and exfiltrates them via HTTP POST to hxxps://polymarket-clob-service[.]vercel[.]app/api/v1, prepending each file with the system username and local IP address. Any project that imports this package silently leaks its configuration files and credentials to the remote endpoint.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 02:23 PM
analyzed
Jul 2, 2026, 10:58 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.