MAL-2026-17312

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/json-bigint-rs/MAL-2026-17312.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17312
Published
2026-09-30T01:47:59Z
Modified
2026-09-30T03:00:04Z
Summary
Malicious code in json-bigint-rs (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7f5b71b917a0504deb87a597d9d07527179c2d6bb9ec1f836caa34d6145aa043)

On require(), index.js instantiates the shipped json-bigint-rs.wasm module and, for imports declared under the 'wasm:js/string-constants' module namespace, exposes each descriptor's name as an externref global. This mechanism smuggles a full JavaScript payload as WASM import-descriptor names, hiding it from JS-only source scanners. The reconstructed payload is an IIFE wired to node:vm.runInThisContext / runInNewContext that polls three hardcoded hosts (rs.undotest.top, rs.lightnight.top, rs.belivelight.top) every 30 seconds and executes the response body as JavaScript in-process with access to console and process. Execution is gated by NODE_ENV==='production', so the dropper stays dormant on developer machines and activates on servers and CI. The remote hosts are mutable and unrelated to any documented publisher; the behavior is undocumented in README. The package name and stated purpose (a bignum JSON parser) provide cover for a delivery vehicle whose only observable install/require-time effect is fetching and evaluating attacker-chosen JavaScript.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020793",
            "import_time":  "2026-09-30T02:52:56.882168345Z",
            "modified_time":  "2026-09-30T01:47:59Z",
            "sha256":  "7f5b71b917a0504deb87a597d9d07527179c2d6bb9ec1f836caa34d6145aa043",
            "source":  "amazon-inspector",
            "versions":  [
                "0.1.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / json-bigint-rs

Package

Name
json-bigint-rs
View open source insights on deps.dev
Purl
pkg:npm/json-bigint-rs

Affected ranges

Affected versions

0.*
0.1.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "json-bigint-rs.wasm",
            "sha256":  "d040c3632590b3c2199c0d737aff07e9310b2e182328759d4722adc24572e90b",
            "tlsh":  "64a2d707b52f24acb341a4360a5985363b5f0c40f169a6b2f74d647a6fffa19b4d3b20"
        },
        {
            "path":  "index.js",
            "sha256":  "83cc133b5ef9e956ebe9ca7faa4d5e893b958fa51f0548b59d81092b7a7977f5",
            "tlsh":  "d491870e7df2e09146e3a2a49c5b941925388121b038edeaf5ec43d42fd1569cbb6fcd"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "json-bigint-rs-0.1.1.tgz",
            "hashes":  {
                "sha1":  "7098a869051bad5c71d5d2bf04a798df0c4be16f",
                "sha512_sri":  "sha512-ezvCHb2kJ6IBmGnYSerUSDoBiQzGBzI/7sREGzeRl7oRNP83HFQDWNgPGb+4uz3ZavQ4mTxMRiOreZS7ggeLkw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/json-bigint-rs/MAL-2026-17312.json"