Malware Manipulates AI Detection in Latest npm Package Breach
ID: 2d7bc1b9-5ea1-537b-8bb7-133a59f11831
STIX ID: report--2d7bc1b9-5ea1-537b-8bb7-133a59f11831
Feed Name: Infosecurity Magazine (News)
A malicious npm package (eslint-plugin-unicorn-ts-2, v1.2.1) masquerading as an ESLint plugin was found to contain no linting functionality but instead executed a post-install hook that harvested environment variables and exfiltrated them to a Pipedream webhook. The package used typosquatting, had nearly 17,000 installs, and embedded a prompt designed to manipulate LLM-based code scanners; earlier malicious versions were flagged by OpenSSF but the package remained available on the registry, raising supply-chain security concerns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
