MAL-2026-17302

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/solidity-lock/MAL-2026-17302.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17302
Published
2026-09-30T00:45:21Z
Modified
2026-09-30T01:00:06Z
Summary
Malicious code in solidity-lock (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7e283fd2d07e81705e23d5756d15edd4ff4dc7a074d375111155ef9dca1fd9b8)

The package's declared main index.js is a trivial no-op Express middleware whose only real effect is to require('./lib/config'), a ~4 MB obfuscator.io-style bundle (rotating string array, hex-escaped entries, self-executing IIFE) that runs at import time. Package identity does not match the shipped code: package.json name is 'solidity-lock' with a vulnerability-management description, keywords advertise a logger ('fast','logger','stream','json'), scripts are 'smoke:pino'/'smoke:file', the README is a copy of pino's README with the name changed, and index.d.ts references pinojs/pino — three inconsistent cover stories layered over the opaque payload. axios ^1.10.0 is declared as a dependency but is not referenced anywhere in the plain-text sources; the only plausible consumer is the obfuscated blob, consistent with outbound HTTP from the hidden payload. Any process that requires this package executes the obfuscated bundle in-process with full host privileges.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020750",
            "import_time":  "2026-09-30T00:52:54.525570247Z",
            "modified_time":  "2026-09-30T00:45:21Z",
            "sha256":  "7e283fd2d07e81705e23d5756d15edd4ff4dc7a074d375111155ef9dca1fd9b8",
            "source":  "amazon-inspector",
            "versions":  [
                "2.21.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / solidity-lock

Package

Name
solidity-lock
View open source insights on deps.dev
Purl
pkg:npm/solidity-lock

Affected ranges

Affected versions

2.*
2.21.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "lib/config.js",
            "sha256":  "3a7f87ca7f738984bd7918a88da35a9898a491fd969e4ff43e619b25f2394abb",
            "tlsh":  "f0168345b287bc2742cf2663be0139ec7467656284c8a18bcb56bd1d35bc80bd9e6fd0"
        },
        {
            "path":  "package.json",
            "sha256":  "314f8bb8b7bf0aa37f5efa1f1473f51944a847e97df897124dd5be94a827876f",
            "tlsh":  "65019920deb88e2301ed25424c2a4643b6b58c175628fc2932dba12c4f9d5ff01ff22d"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "solidity-lock-2.21.0.tgz",
            "hashes":  {
                "sha1":  "15f5e804326dad2bad1ab4eec01a905e878b40c0",
                "sha512_sri":  "sha512-wbuBxiGTIyEChQ3tYe+OBVJo6AakMIs6tQiKHmLsfobFIh5nJPbF5gC7Gd+JMZv//U0YzOrasNIzHv45u02nqw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/solidity-lock/MAL-2026-17302.json"