@across-toolkit/eslint-config@99.0.1
Malicious code in @across-toolkit/eslint-config (npm)
Analysis
Dependency-confusion package impersonating the Across Protocol toolkit's ESLint config. On install, the postinstall.js hook collects cloud metadata from GCP (metadata.google.internal) and AWS (169[.]254[.]169[.]254), runs gcloud CLI to extract access tokens, reads credential files including ~/.aws/credentials, ~/.npmrc, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.config/gcloud/*, /etc/environment, and .env files, and captures environment variables (NPM_TOKEN, GITHUB_TOKEN, GH_TOKEN, Actions OIDC tokens). All stolen data is exfiltrated as a JSON POST to webhook[.]site/a585f4ec-20f7-4bd1-bac7-f3e53799dc5f.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 12:36 PM
- analyzed
- Jul 16, 2026, 12:36 PM
Related advisories
- @across-toolkit/eslint-config@99.0.0 same package
- @across-toolkit/typescript-config@99.0.1
- @across-toolkit/typescript-config@99.0.0
- antsrcsrctest@1.0.0
- hello244b@1.0.0
- stream-read-35cf@1.0.0
- buffer-wrap-67d7@1.0.0
- textdecode@1.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.