-= Per source details. Do not edit below this line.=-
The package's declared main index.js is a trivial no-op Express middleware whose only real effect is to require('./lib/config'), a ~4 MB obfuscator.io-style bundle (rotating string array, hex-escaped entries, self-executing IIFE) that runs at import time. Package identity does not match the shipped code: package.json name is 'solidity-lock' with a vulnerability-management description, keywords advertise a logger ('fast','logger','stream','json'), scripts are 'smoke:pino'/'smoke:file', the README is a copy of pino's README with the name changed, and index.d.ts references pinojs/pino — three inconsistent cover stories layered over the opaque payload. axios ^1.10.0 is declared as a dependency but is not referenced anywhere in the plain-text sources; the only plausible consumer is the obfuscated blob, consistent with outbound HTTP from the hidden payload. Any process that requires this package executes the obfuscated bundle in-process with full host privileges.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020750",
"import_time": "2026-09-30T00:52:54.525570247Z",
"modified_time": "2026-09-30T00:45:21Z",
"sha256": "7e283fd2d07e81705e23d5756d15edd4ff4dc7a074d375111155ef9dca1fd9b8",
"source": "amazon-inspector",
"versions": [
"2.21.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "lib/config.js",
"sha256": "3a7f87ca7f738984bd7918a88da35a9898a491fd969e4ff43e619b25f2394abb",
"tlsh": "f0168345b287bc2742cf2663be0139ec7467656284c8a18bcb56bd1d35bc80bd9e6fd0"
},
{
"path": "package.json",
"sha256": "314f8bb8b7bf0aa37f5efa1f1473f51944a847e97df897124dd5be94a827876f",
"tlsh": "65019920deb88e2301ed25424c2a4643b6b58c175628fc2932dba12c4f9d5ff01ff22d"
}
],
"package_integrity": [
{
"filename": "solidity-lock-2.21.0.tgz",
"hashes": {
"sha1": "15f5e804326dad2bad1ab4eec01a905e878b40c0",
"sha512_sri": "sha512-wbuBxiGTIyEChQ3tYe+OBVJo6AakMIs6tQiKHmLsfobFIh5nJPbF5gC7Gd+JMZv//U0YzOrasNIzHv45u02nqw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/solidity-lock/MAL-2026-17302.json"