MAL-2026-17157
Malicious code in eslint-config-compact-base (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (dbc01e3a8316b2d4e11b34a9c8cbe1cf5bd2af83a6a70052e40a22b54f13f78b) index.js executes on module load and collects host reconnaissance data — os.platform(), os.hostname(), os.userInfo().username, architecture, Node version, current working directory — together with CI-context environment variables including CI, RUNNER_NAME, and GITHUB_REPOSITORY. The collected values are serialized as query-string parameters and sent via https.get to the hardcoded endpoint https://cbrsuo9293.execute-api.us-east-1.amazonaws.com/c. The behavior fires unconditionally on require(), so any build, install, or CI job that pulls in this ESLint config beacons its host identity and repository name to the attacker-controlled AWS API Gateway. This network activity has no relationship to the package's advertised purpose as an ESLint configuration.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for eslint-config-compact-base (npm). Pin to a known-safe version or switch to an alternative.