LWA-2026-6846 MAL-2026-10703 ↗ confirmed malware

@across-toolkit/eslint-config@99.0.1

Malicious code in @across-toolkit/eslint-config (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1525 · Implant Internal ImageT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion package impersonating the Across Protocol toolkit's ESLint config. On install, the postinstall.js hook collects cloud metadata from GCP (metadata.google.internal) and AWS (169[.]254[.]169[.]254), runs gcloud CLI to extract access tokens, reads credential files including ~/.aws/credentials, ~/.npmrc, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.config/gcloud/*, /etc/environment, and .env files, and captures environment variables (NPM_TOKEN, GITHUB_TOKEN, GH_TOKEN, Actions OIDC tokens). All stolen data is exfiltrated as a JSON POST to webhook[.]site/a585f4ec-20f7-4bd1-bac7-f3e53799dc5f.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 12:36 PM
analyzed
Jul 16, 2026, 12:36 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.