-= Per source details. Do not edit below this line.=-
common-fs advertises itself as a filesystem/transaction helper but ships an obfuscated code loader. index.js reconstructs the identifiers 'Function', 'Buffer', 'require', 'process', and 'setTimeout' from a shuffled string-array and obtains the Function constructor indirectly via global.constructor.constructor, hiding the eval sink from casual review. The documented getTransactions() entry point calls load_transaction_data(), which reads the sibling file use.js, treats it as a product catalog, concatenates the per-entry 'mark' fields in id order, applies a base64 + Caesar-shift decode followed by another base64 decode, and executes the resulting bytes with the Function constructor while injecting Buffer, require, and process. use.js is not data; it is the payload container, split across many small 'mark' fields to defeat string search. The moment a consumer calls the library's advertised API, attacker-controlled JavaScript runs in the caller's process with full access to require and process — enabling arbitrary code execution, filesystem access, and network exfiltration on the installer's host.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020697",
"import_time": "2026-09-29T23:39:24.473274308Z",
"modified_time": "2026-09-29T23:24:07Z",
"sha256": "e3d99fa69df24bb5170c840f84e44038c20cf8b431c94abfd57eaa3701593684",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "72a7f942cc38326c29c48b536fa49f166c8d4d544b43da66893c2e9a59fffab0",
"tlsh": "83f10f6c39f930248857b07c67eb9449612de0576e9a6ca87f4d83101f7d13ce1f6ba8"
},
{
"path": "use.js",
"sha256": "65b54532c82855bbc8055c67d9f53854737ce01d3ae6b95fc6577204b81d953f",
"tlsh": "4e331f3acb780c5b91795a606af50a4af280471f17a16d877fbcd54c8fb1c5b804ab3b"
}
],
"package_integrity": [
{
"filename": "common-fs-1.0.0.tgz",
"hashes": {
"sha1": "f1611cb60db31fe0bd5ab0c72e94bd05c0557cfe",
"sha512_sri": "sha512-gZOgk2GPU3Eh2dcdKyMOAUaakS7XykK2QCgtOI3IMR+kkMO09+rC90uDXn8X8ALyZTtzkWa7bkIF4k5+1tDv5w=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/common-fs/MAL-2026-17300.json"