An ESLint maintainer's npm account was compromised via credential stuffing (password reused, no 2FA). A malicious postinstall script in eslint-scope@3.7.2 exfiltrated .npmrc auth tokens to pastebin.com, designed as a worm to steal tokens for further package compromises. Approximately 4,500 accounts had tokens potentially exposed; npm revoked ALL tokens issued before the incident.
Sources: ESLint postmortem · Microsoft Azure DevOps response · NodeSource observer account
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS |
| Socket | Caught | Behavioral analysis detects malicious payload. |
| Snyk | Missed | No malware detection capability |
| Sonatype (Nexus) | Caught | Nexus Firewall blocks known-malicious packages at ingestion |
| Black Duck | Missed | No malware detection capability |
| Endor Labs | Missed | No malware detection capability |