OpenSSF/OSV advisory MAL-2026-10076 confirms this npm version as malicious. The package ts-eslint-jest@1.0.0 presents as a TypeScript/ESLint/Jest helper but ships lib/collect.js, which imports child_process and invokes execSync('bash...') at line 205 and execSync('zsh...') at line 221...
Package ships high-entropy non-source blobs.
data-backup-single.rarView on unpkgPackage ships compressed or archive-like blobs.
data-backup-single.rarView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
data-backup-single.rarView on unpkgPackage source closely matches a different published package identity; review for dependency-confusion or copied-code abuse.
lib/collect.jsView on unpkgPackage ships high-entropy non-source blobs.
data-backup-single.rarView on unpkgPackage ships compressed or archive-like blobs.
data-backup-single.rarView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
data-backup-single.rarView on unpkgPackage source closely matches a different published package identity; review for dependency-confusion or copied-code abuse.
lib/collect.jsView on unpkg