LWA-2026-7696 MAL-2026-11753 ↗ confirmed malware

@ornikar/eslint-config-typescript-react@24.0.1

Malicious code in @ornikar/eslint-config-typescript-react (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1027 · Obfuscated Files or InformationT1105 · Ingress Tool Transfer

Analysis

Version 24.0.1 of this ESLint config package is a trojanized release. The preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun and uses it to execute a 727KB obfuscated payload file (math_init.js). The legitimate ESLint config files are still present in the package to disguise the attack. The package size jumped from ~42KB to 780KB, and the preinstall hook was added for the first time in 171 versions. The payload's runtime behaviour is concealed by heavy obfuscation and Bun-compiled bytecode.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 10:19 AM
analyzed
Aug 4, 2026, 10:20 AM
weekly installs
662

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.