VDB
EN

MAL-2026-13980

Malicious code in eslint-generate-release (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4478598213eba844460a99bf323ef024e2fb906c918736cc7e593745029e16b4) eslint-generate-release@99.9.1 is a hollow package whose index.js exports an empty object and whose only effect on install is dependency resolution. package.json declares a runtime dependency `ltidisafe` whose version specifier is not an npm-registry version but a direct HTTPS tarball URL: https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.6.3.tgz. On `npm install`, npm fetches and installs that off-registry tarball into node_modules, introducing code that never passed through the npm registry. The package name mimics the ESLint ecosystem and the 99.9.1 version is a version-squat pattern; combined with the empty main entry, the package functions purely as a smuggling wrapper for the URL-referenced payload.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / eslint-generate-release

No fixed version published yet for eslint-generate-release (npm). Pin to a known-safe version or switch to an alternative.

참고