MAL-2026-13461

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/supersig/MAL-2026-13461.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13461
Published
2026-08-06T19:43:53Z
Modified
2026-08-06T23:50:22.893960967Z
Summary
Malicious code in supersig (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (557f8e62aa65bb4fe5e96a52cf6c5ba83c2f1bcf47eca3027bf4daca071249e5)

The published dist bundles (dist/supersig.cjs.js, dist/supersig.esm.js, dist/supersig.umd.js), reached via the package's main/module/browser entries on require/import, contain a decrypt-and-execute chain that is absent from the src/ tree. The bundles import a DES key from an unpinned dependency mkb-manager@latest, call decryptToken on an embedded encrypted token to produce plaintext code, spawn a fresh node child process via childprocess.spawn('node', [],...), and write the decrypted bytes into that process's stdin (rsaexec.stdin.write / desexec.stdin.write). Any consumer that requires or imports this package executes the decrypted payload at load time. Because mkb-manager is pinned to latest, whoever controls that package can rotate the decryption key/payload at will, making the executed code opaque and mutable. The src/ wallet, signers, providers, and transactions modules contain no decryptToken, readRSAFromPackage, mkb-manager, or childprocess usage — the dropper is present only in the shipped bundles, indicating deliberate concealment from source-tree review.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-08-06T19:43:53Z",
            "source": "amazon-inspector",
            "sha256": "557f8e62aa65bb4fe5e96a52cf6c5ba83c2f1bcf47eca3027bf4daca071249e5",
            "import_time": "2026-08-06T23:25:10.619571708Z",
            "id": "IN-MAL-2026-016813",
            "versions": [
                "1.0.5"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / supersig

Package

Affected ranges

Affected versions

1.*
1.0.5

Database specific

indicators
{
    "package_integrity": [
        {
            "filename": "supersig-1.0.5.tgz",
            "hashes": {
                "sha512_sri": "sha512-il+4T69vaxaN3aGas+FQgWncx96ofBwDK5uBRPGKcWzuBE99OuwLl//OSVdhRd1Ycr3f+HsVDZUDCjlYB2qgCw==",
                "sha1": "59af53fde948ec76c145066bd20ffcad8fb86006"
            }
        }
    ],
    "evidence_files": [
        {
            "tlsh": "1b63949d26e7a060815b70b56fdb94407129e00b68ccd82cbdac53958fd946c9bf2ff8",
            "sha256": "3962046de135cac3fbbcfbc6bde64ecc4ed5f0e5633738220e928e2901859bc9",
            "path": "dist/supersig.esm.js"
        },
        {
            "tlsh": "cf63939d26e7a060815b70b56fdb94407129e00b68ccd82cbdac53958fd946c9bf2ff8",
            "sha256": "7776d30e6fe4073e6bbf09c93e7ae92f1b2109dd8543683fb3aeb5ccb6d76679",
            "path": "dist/supersig.cjs.js"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/supersig/MAL-2026-13461.json"
cwes
[
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]