@ornikar/eslint-config-typescript-react@24.0.1
Malicious code in @ornikar/eslint-config-typescript-react (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1027 · Obfuscated Files or InformationT1105 · Ingress Tool Transfer
Analysis
Version 24.0.1 of this ESLint config package is a trojanized release. The preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun and uses it to execute a 727KB obfuscated payload file (math_init.js). The legitimate ESLint config files are still present in the package to disguise the attack. The package size jumped from ~42KB to 780KB, and the preinstall hook was added for the first time in 171 versions. The payload's runtime behaviour is concealed by heavy obfuscation and Bun-compiled bytecode.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 10:19 AM
- analyzed
- Aug 4, 2026, 10:20 AM
- weekly installs
- 662
Related advisories
- @ornikar/prismic-components@0.0.8
- @ornikar/rollup-plugin-postcss@2.0.10
- @ornikar/react-native-svg-transformer@1.0.10
- bigops-create-manifest@35.2.4
- bigops-cobrowsing-client@35.1.9
- bigops-chat-transfer@35.3.6
- bigops-informer@35.4.8
- entropyeasybots@2.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.