{"id":"MAL-2026-17157","summary":"Malicious code in eslint-config-compact-base (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dbc01e3a8316b2d4e11b34a9c8cbe1cf5bd2af83a6a70052e40a22b54f13f78b)\nindex.js executes on module load and collects host reconnaissance data — os.platform(), os.hostname(), os.userInfo().username, architecture, Node version, current working directory — together with CI-context environment variables including CI, RUNNER_NAME, and GITHUB_REPOSITORY. The collected values are serialized as query-string parameters and sent via https.get to the hardcoded endpoint https://cbrsuo9293.execute-api.us-east-1.amazonaws.com/c. The behavior fires unconditionally on require(), so any build, install, or CI job that pulls in this ESLint config beacons its host identity and repository name to the attacker-controlled AWS API Gateway. This network activity has no relationship to the package's advertised purpose as an ESLint configuration.\n","modified":"2026-09-24T13:30:05.128160334Z","published":"2026-09-24T13:17:49Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-24T13:17:49Z","sha256":"dbc01e3a8316b2d4e11b34a9c8cbe1cf5bd2af83a6a70052e40a22b54f13f78b","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020511","import_time":"2026-09-24T13:18:04.716839408Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/eslint-config-compact-base/v/1.0.0"}],"affected":[{"package":{"name":"eslint-config-compact-base","ecosystem":"npm","purl":"pkg:npm/eslint-config-compact-base"},"versions":["1.0.0"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"c518a6545d4699ac8e9c12aa4611bd46000c4123","sha512_sri":"sha512-28zvkl5Nc4U5PXk/dU2XKYSi0mtCVV03MOS05Uf2ueKRhXm4KPccfYqCRL48CCGuw32bqbcSQJIL12Nvr43Iuw=="},"filename":"eslint-config-compact-base-1.0.0.tgz"}],"evidence_files":[{"tlsh":"7101f8f2aa9c483a21d63200c40f000aead7d63309c8f2b05a2a926c6f3493613b1378","path":"index.js","sha256":"a87b6a34e6c9edb4a7c0223eaa3687f6d253b2e3bf68aa3548b60f362d200f51"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/eslint-config-compact-base/MAL-2026-17157.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}