Official eslint package with only expected files and a single benign network check to eslint.org. No malicious behavior present.
AI breakdown
Plain-English summary of what this package does and how it behaves.
ESLint is an AST-based pattern checker for JavaScript that provides a CLI tool and programmatic API for linting code against configurable rules.
Capabilities
- Provides CLI via bin/eslint.js
- Includes extensive set of JavaScript linting rules
- Uses cross-spawn dependency for child processes
- Supports build/test/release scripts via node
Data access
- Filesystem
- Environment variables
Network
- No network access observed
Widely used open-source linter with many dependencies; review source and updates before integrating into build pipelines.
Dependency & execution chain
Every package this one pulls in, colored by verdict. Expand to walk the tree.
Outbound network destinations
Hosts contacted during sandbox execution, geo-located from resolved IPs.
Destinations were observed but could not be geo-located to map coordinates.
| Host | IP | Location | Port |
|---|---|---|---|
| eslint.org | 13.52.188.95 | — | 443 |
| eslint.org | 52.52.192.191 | — | 443 |
Files in package (500)
How ShadowCanopy checks npm packages
ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.
This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/eslint