top of page

Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools

2 december 2025 om 14:17:00

thehackernews.com

Cybersecurity researchers discovered a malicious npm package named eslint-plugin-unicorn-ts-2 that attempts to evade AI-driven security scanners. The package masquerades as a TypeScript extension of the popular ESLint plugin and was uploaded by user 'hamburgerisland' in February 2024. The malicious package uses hidden prompts and scripts specifically designed to influence and bypass artificial intelligence-based security scanning tools. This represents a new evolution in supply chain attacks targeting the npm ecosystem, where attackers are now adapting their techniques to counter AI-powered security defenses.

Related links:

Related CVE's:

No CVEs found in this article

Related threat actors:

HAMBURGERISLAND

Affected products:

npmESLint

IOC's:

eslint-plugin-unicorn-ts-2

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page