mjs-eslint@7.0.7
Malicious code in mjs-eslint (npm)
Analysis
mjs-eslint@7.0.7 is a trojanized clone of the legitimate big.js library. It copies the entire big.js source tree verbatim but injects a require('ts-eslint-helper') call at line 605 of both big.js and big.mjs that executes at module evaluation time. The ts-eslint-helper dependency recursively searches the current working directory for credential and configuration files (id.json, config.toml, config.json, .env, env) and exfiltrates them via HTTP POST to hxxps://polymarket-clob-service[.]vercel[.]app/api/v1, prepending each file with the system username and local IP address. Any project that imports this package silently leaks its configuration files and credentials to the remote endpoint.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 02:23 PM
- analyzed
- Jul 2, 2026, 10:58 AM
Related advisories
- @marketfront/actualordersnippetpopup@7.0.0
- date-fns-lite@1.0.6
- ecto-cargo-wk1tm59a@99.0.0
- cursed-modules@999.0.0
- auth-next-gen@1.6.29
- ripshakti1@81.0.0
- ripshakti@80.0.0
- ts-linting-builder@2.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.