-= Per source details. Do not edit below this line.=-
The published dist bundles (dist/supersig.cjs.js, dist/supersig.esm.js, dist/supersig.umd.js), reached via the package's main/module/browser entries on require/import, contain a decrypt-and-execute chain that is absent from the src/ tree. The bundles import a DES key from an unpinned dependency mkb-manager@latest, call decryptToken on an embedded encrypted token to produce plaintext code, spawn a fresh node child process via childprocess.spawn('node', [],...), and write the decrypted bytes into that process's stdin (rsaexec.stdin.write / desexec.stdin.write). Any consumer that requires or imports this package executes the decrypted payload at load time. Because mkb-manager is pinned to latest, whoever controls that package can rotate the decryption key/payload at will, making the executed code opaque and mutable. The src/ wallet, signers, providers, and transactions modules contain no decryptToken, readRSAFromPackage, mkb-manager, or childprocess usage — the dropper is present only in the shipped bundles, indicating deliberate concealment from source-tree review.
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-06T19:43:53Z",
"source": "amazon-inspector",
"sha256": "557f8e62aa65bb4fe5e96a52cf6c5ba83c2f1bcf47eca3027bf4daca071249e5",
"import_time": "2026-08-06T23:25:10.619571708Z",
"id": "IN-MAL-2026-016813",
"versions": [
"1.0.5"
]
}
]
}{
"package_integrity": [
{
"filename": "supersig-1.0.5.tgz",
"hashes": {
"sha512_sri": "sha512-il+4T69vaxaN3aGas+FQgWncx96ofBwDK5uBRPGKcWzuBE99OuwLl//OSVdhRd1Ycr3f+HsVDZUDCjlYB2qgCw==",
"sha1": "59af53fde948ec76c145066bd20ffcad8fb86006"
}
}
],
"evidence_files": [
{
"tlsh": "1b63949d26e7a060815b70b56fdb94407129e00b68ccd82cbdac53958fd946c9bf2ff8",
"sha256": "3962046de135cac3fbbcfbc6bde64ecc4ed5f0e5633738220e928e2901859bc9",
"path": "dist/supersig.esm.js"
},
{
"tlsh": "cf63939d26e7a060815b70b56fdb94407129e00b68ccd82cbdac53958fd946c9bf2ff8",
"sha256": "7776d30e6fe4073e6bbf09c93e7ae92f1b2109dd8543683fb3aeb5ccb6d76679",
"path": "dist/supersig.cjs.js"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/supersig/MAL-2026-13461.json"
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]