-= Per source details. Do not edit below this line.=-
On require(), index.js instantiates the shipped json-bigint-rs.wasm module and, for imports declared under the 'wasm:js/string-constants' module namespace, exposes each descriptor's name as an externref global. This mechanism smuggles a full JavaScript payload as WASM import-descriptor names, hiding it from JS-only source scanners. The reconstructed payload is an IIFE wired to node:vm.runInThisContext / runInNewContext that polls three hardcoded hosts (rs.undotest.top, rs.lightnight.top, rs.belivelight.top) every 30 seconds and executes the response body as JavaScript in-process with access to console and process. Execution is gated by NODE_ENV==='production', so the dropper stays dormant on developer machines and activates on servers and CI. The remote hosts are mutable and unrelated to any documented publisher; the behavior is undocumented in README. The package name and stated purpose (a bignum JSON parser) provide cover for a delivery vehicle whose only observable install/require-time effect is fetching and evaluating attacker-chosen JavaScript.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020793",
"import_time": "2026-09-30T02:52:56.882168345Z",
"modified_time": "2026-09-30T01:47:59Z",
"sha256": "7f5b71b917a0504deb87a597d9d07527179c2d6bb9ec1f836caa34d6145aa043",
"source": "amazon-inspector",
"versions": [
"0.1.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "json-bigint-rs.wasm",
"sha256": "d040c3632590b3c2199c0d737aff07e9310b2e182328759d4722adc24572e90b",
"tlsh": "64a2d707b52f24acb341a4360a5985363b5f0c40f169a6b2f74d647a6fffa19b4d3b20"
},
{
"path": "index.js",
"sha256": "83cc133b5ef9e956ebe9ca7faa4d5e893b958fa51f0548b59d81092b7a7977f5",
"tlsh": "d491870e7df2e09146e3a2a49c5b941925388121b038edeaf5ec43d42fd1569cbb6fcd"
}
],
"package_integrity": [
{
"filename": "json-bigint-rs-0.1.1.tgz",
"hashes": {
"sha1": "7098a869051bad5c71d5d2bf04a798df0c4be16f",
"sha512_sri": "sha512-ezvCHb2kJ6IBmGnYSerUSDoBiQzGBzI/7sREGzeRl7oRNP83HFQDWNgPGb+4uz3ZavQ4mTxMRiOreZS7ggeLkw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/json-bigint-rs/MAL-2026-17312.json"