@across-toolkit/eslint-config@99.0.0
Malicious code in @across-toolkit/eslint-config (npm)
Analysis
@across-toolkit/eslint-config@99.0.0 is a dependency-confusion package impersonating the Across Protocol toolkit. On install, the postinstall.js hook harvests cloud metadata credentials from GCP (metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token) and AWS (169[.]254[.]169[.]254/latest/meta-data/iam/security-credentials/), reads local credential files (~/.aws/credentials, ~/.npmrc, ~/.ssh/id_rsa, ~/.config/gcloud/application_default_credentials.json, .env, .env.local, /proc/1/environ), dumps the entire process environment, and exfiltrates everything via HTTPS POST to webhook[.]site/a585f4ec-20f7-4bd1-bac7-f3e53799dc5f.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 12:45 PM
- analyzed
- Jul 16, 2026, 04:40 PM
Related advisories
- @across-toolkit/eslint-config@99.0.1 same package
- @across-toolkit/typescript-config@99.0.1
- @across-toolkit/typescript-config@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.