ts-eslint-jest@1.0.0
Malicious code in ts-eslint-jest (npm)
Analysis
ts-eslint-jest is a combosquat of the legitimate eslint-jest package. When the test script is run (npm test), it executes a credential-theft implant that: (1) scans the victim's project directory and home directory for crypto wallet files — EVM private keys, Solana key arrays, mnemonic/seed phrases, keystores (UTC--*, wallet.json, keypair.json), and hardhat/foundry configs; (2) extracts dev secrets including AWS secret access keys, API tokens, and npm tokens from source files; (3) reads shell history from bash, zsh, fish, and PowerShell; (4) captures clipboard content via pbpaste (macOS), wl-paste/xclip (Linux), or PowerShell Get-Clipboard (Windows); (5) collects .env, config files, and .pem/.p12/.pfx private key files. All stolen data is exfiltrated via multipart HTTP POST to hxxps://trabalhos-flax[.]vercel[.]app/api/v1. The package also ships a bundled RAR archive (data-backup-single.rar).
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 08:26 AM
- analyzed
- Jul 9, 2026, 08:28 AM
Related advisories
- jest-formatter@1.0.0
- express-mongo-limit@2.0.1
- pinokio-redis@1.0.127
- zredis-typed@1.0.127
- zod-pino434@1.0.127
- crypto-base58@1.0.1
- pino-zod@1.0.121
- zod-pino@1.0.122
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.