On October 10, 2026 (local time), boom() calls localStorage.setItem('key', i) 100,000,000 times in a synchronous loop, potentially freezing a browser page. In version 0.0.2, the exported getCommonDateInRanges() calls boom() before input validation; the bundled source map confirms this path. Version 0.0.3 retains boom() as a separate export but no longer calls it from getCommonDateInRanges(), so an explicit call is required. Version 0.0.1 does not contain this routine. This is a static finding; actual victim impact was not observed.
[
{
"cweId": "CWE-400",
"description": "The product does not properly control the allocation and maintenance of a limited resource.",
"name": "Uncontrolled Resource Consumption"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/future-scripts/MAL-2026-17418.json"