{
"ecosystem": "npm",
"count": 100,
"threats": [
{
"id": "c657f9f3-a270-44ee-8fc3-e986d282d132",
"created\_at": "2026-06-20T02:24:23.546471\+00:00",
"updated\_at": "2026-06-20T22:06:54.468\+00:00",
"report\_type": "package",
"severity\_level": "high",
"status": "verified",
"verified\_at": "2026-06-20T22:06:54.468\+00:00",
"first\_seen": "2026-06-20T02:24:19.87\+00:00",
"last\_seen": null,
"registry": "npm",
"resource\_identifier": "npm/new-eslint-1",
"package\_name": "new-eslint-1",
"download\_count": null,
"published\_date": null,
"tags": \[
"npm",
"compromised-account",
"entry-main",
"suspicious-metadata",
\],
"version\_info": "7.0.6",
"source\_id": null,
"threat\_description": "Malicious package detected.",
"payload\_description": "ENTRY\\n big.mjs (main: big.mjs)\\n\\nADDITIONAL FINDINGS\\n - Very New NPM Publisher Account\\n - Publisher Has Other Malicious Packages\\n - Publisher Shows Burner-Account Pattern\\n\\nINDICATORS (IOCs)\\n - urls: [http://mikemcl.github.io/big.js/](http://mikemcl.github.io/big.js/), [https://deno.land/](https://deno.land/), [https://www.coinbase.com/\\n](https://www.coinbase.com/\n) - domains: [mikemcl.github.io](http://mikemcl.github.io), [www.coinbase.com](http://www.coinbase.com), [deno.land](http://deno.land)\\n - emails: start@yc.length, adding@yc.length",
"evidence\_references": null,
"verified\_by": "6mile",
"osv\_advisory\_url": "[https://osv.dev/vulnerability/MAL-2026-6225](https://osv.dev/vulnerability/MAL-2026-6225)",
"ghsa\_advisory\_url": null,
"researcher": null,
"researcher\_organization": null,
"malicious\_dependencies": \[\]
}
\]
}