LWA-2026-6481 MAL-2026-10076 ↗ confirmed malware

ts-eslint-jest@1.0.0

Malicious code in ts-eslint-jest (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1115 · Clipboard DataT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

ts-eslint-jest is a combosquat of the legitimate eslint-jest package. When the test script is run (npm test), it executes a credential-theft implant that: (1) scans the victim's project directory and home directory for crypto wallet files — EVM private keys, Solana key arrays, mnemonic/seed phrases, keystores (UTC--*, wallet.json, keypair.json), and hardhat/foundry configs; (2) extracts dev secrets including AWS secret access keys, API tokens, and npm tokens from source files; (3) reads shell history from bash, zsh, fish, and PowerShell; (4) captures clipboard content via pbpaste (macOS), wl-paste/xclip (Linux), or PowerShell Get-Clipboard (Windows); (5) collects .env, config files, and .pem/.p12/.pfx private key files. All stolen data is exfiltrated via multipart HTTP POST to hxxps://trabalhos-flax[.]vercel[.]app/api/v1. The package also ships a bundled RAR archive (data-backup-single.rar).

analyzed by
Leitwacht
first seen
Jul 9, 2026, 08:26 AM
analyzed
Jul 9, 2026, 08:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.