Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious npm Package Typosquats Popular TypeScript ESLint P...

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
998
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

Attackers exploited the open-source ecosystem by typosquatting a popular TypeScript ESLint plugin, @typescript-eslint/eslint-plugin, to distribute a malicious npm package, @typescript_eslinter/eslint, which compromised developer systems by exfiltrating data and allowing remote command execution. The malicious package closely mimicked the legitimate one, deceiving developers and enabling the attackers to steal sensitive information such as API keys and credentials through clipboard and keyboard monitoring, while also establishing persistence by embedding itself into the system's startup routine. Despite the removal of the primary malicious package from npm, its secondary payload, @typescript_eslinter/prettier, remains active, continuing to pose a threat. The attack highlights the need for effective typosquatting detection tools, which can prevent such open-source supply chain attacks and protect the integrity of development environments.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.