CRITICAL npm Malware

Malicious code in eslint-plugin-i18n-shreddit (npm)

MAL-2026-16437

Published · Modified

Dependency scanning

Check whether eslint-plugin-i18n-shreddit is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (3a22687900b0decfe83eda7516ec5c5169401894c98be27d115e5dffe64fc902)

eslint-plugin-i18n-shreddit@99.9.9 ships no ESLint plugin code; the tarball's only function is a postinstall hook (scripts.postinstall = 'node index.js') that runs automatically on npm install. index.js collects installer-side reconnaissance — os.userInfo().username, process.cwd(), os.hostname(), and the local IPv4 address — and POSTs the values as JSON to a hardcoded anonymous collector at https://webhook.site/f9bff304-3053-4d54-be05-86537267514a. Package metadata is characteristic of a dependency-confusion probe: version 99.9.9 (chosen to win resolution against a lower-versioned internal package of the same name), empty description, empty author, and no exported plugin functionality. Installing this package leaks the installer's identifiers and network position to an attacker-controlled webhook, identifying vulnerable internal build environments for follow-on targeting.

Ready to move

Start Securing

Free, no credit card | First findings in minutes