-= Per source details. Do not edit below this line.=-
Package publishes under a lodash-imitating identity: keywords lodash/lodash-js, and the README is a verbatim copy of the official lodash 4.18.1 README. The single shipped file dist/common-js.js is not lodash — it is a ~770 KB javascript-obfuscator bundle (17,969-entry rotated string array, _0xNNNN identifiers). After deobfuscation the bundle is a browser-based cryptocurrency-mining client: it opens a WebSocket to a caller/config-supplied pool URL, spawns a fan-out of Web Workers keyed by workerId, handles nonce framing, and bundles an AES-GCM decryption primitive (aesGcmDecrypt from @noble/ciphers) for pool message decryption. Wallet and worker identifiers are read from a config object with fallbacks (cfg.wallet||'x', cfg.worker||'worker'). A developer who installs this expecting a lodash-family utility and ships it in a web application will silently mine cryptocurrency on their end users' browsers, consuming visitor CPU/battery and creating a compliance/abuse liability for the downstream site. The identity masquerade (name/keywords/README all mimicking lodash) combined with heavy string-array obfuscation of the real payload is the standard shape of a supply-chain masquerade attack.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-15T17:08:59.179122132Z",
"sha256": "f708a31239d3dc7490906a4a41f5ccb3cb76c99f89bc87b5ad5884939bb2d308",
"modified_time": "2026-08-15T17:07:14Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-017968",
"versions": [
"0.3.4"
]
},
{
"import_time": "2026-08-19T00:21:14.770348651Z",
"sha256": "d3a81522907c6036250cd04caf2b6350ad1903fd50ed138cda550ec33a1a7ea0",
"modified_time": "2026-08-19T00:06:31Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018266",
"versions": [
"0.3.6"
]
},
{
"import_time": "2026-08-19T00:21:14.953987143Z",
"sha256": "832d1ce61ce1f1e1430c60e94175cc80700dfbb2f8d0f46fd7d00b64720026d8",
"modified_time": "2026-08-19T00:06:46Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018268",
"versions": [
"0.3.10"
]
},
{
"import_time": "2026-08-19T00:21:14.876006876Z",
"sha256": "858e186e40af34fa05e49209b9bfeb758f4b734da30dacd6bd66cdb5c77a368b",
"modified_time": "2026-08-19T00:06:38Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018267",
"versions": [
"0.3.8"
]
},
{
"import_time": "2026-08-19T00:21:14.695226308Z",
"sha256": "c6fdee952074aa29c57bde30ce12f536868aba1a38faf68a861d856e21cd7f36",
"modified_time": "2026-08-19T00:06:23Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018265",
"versions": [
"0.3.5"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@finaxis/common-js/MAL-2026-14064.json"
{
"evidence_files": [
{
"sha256": "54983b10ced567632cf51c2b732a034924ef73ec11140cc7a2c2a1a5fbe43030",
"path": "dist/common-js.js",
"tlsh": "a604f76562d0b99c13471fb63b2fb0d9dc2d199bb8884b9fe244fc84b5a5317e6d8830"
},
{
"sha256": "ee813ff10e4cddafd9a8ed9619c26b5e226e3de51dea7ae7bf679d9ea3638165",
"tlsh": "d3119e35ccb45e531bd868d60878e152ad2c4e5b9588bd0433d6b04d4a5cabb11fe15c",
"path": "package.json"
}
],
"package_integrity": [
{
"filename": "common-js-0.3.4.tgz",
"hashes": {
"sha1": "27376920a17cb4b1e3a61628876658673ad4b98a",
"sha512_sri": "sha512-coSm5CXVwsqf9p4bYeft02D4VWzET4Qf+E5vpsWLe+48HfGFoAay1hcSBoeya6HnAXZPSai7ZDhbAhLN2k3kFQ=="
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]