LWA-2026-7697 MAL-2026-11752 ↗ confirmed malware

@ornikar/eslint-config-typescript-nestjs@24.0.1

Malicious code in @ornikar/eslint-config-typescript-nestjs (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or InformationT1059 · Command and Scripting Interpreter

Analysis

The package @ornikar/eslint-config-typescript-nestjs@24.0.1 is a trojanized version of a legitimate ESLint configuration package. Version 24.0.1 introduces a preinstall hook (setup.mjs) that downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases/ and executes a 728KB heavily obfuscated script (math_init.js) through it. The obfuscated script uses custom encoding and function-constructor/eval patterns that prevent static analysis of its true behaviour. An ESLint config package has no legitimate reason to download a JavaScript runtime and run obfuscated code on install. The payload's behaviour cannot be determined from static analysis alone due to the obfuscation.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 10:19 AM
analyzed
Aug 4, 2026, 10:21 AM
weekly installs
359

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.