{"id":"MAL-2026-17300","summary":"Malicious code in common-fs (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e3d99fa69df24bb5170c840f84e44038c20cf8b431c94abfd57eaa3701593684)\ncommon-fs advertises itself as a filesystem/transaction helper but ships an obfuscated code loader. index.js reconstructs the identifiers 'Function', 'Buffer', 'require', 'process', and 'setTimeout' from a shuffled string-array and obtains the Function constructor indirectly via global.constructor.constructor, hiding the eval sink from casual review. The documented getTransactions() entry point calls load_transaction_data(), which reads the sibling file use.js, treats it as a product catalog, concatenates the per-entry 'mark' fields in id order, applies a base64 + Caesar-shift decode followed by another base64 decode, and executes the resulting bytes with the Function constructor while injecting Buffer, require, and process. use.js is not data; it is the payload container, split across many small 'mark' fields to defeat string search. The moment a consumer calls the library's advertised API, attacker-controlled JavaScript runs in the caller's process with full access to require and process — enabling arbitrary code execution, filesystem access, and network exfiltration on the installer's host.\n","modified":"2026-09-29T23:45:38.013965339Z","published":"2026-09-29T23:24:07Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-020697","import_time":"2026-09-29T23:39:24.473274308Z","modified_time":"2026-09-29T23:24:07Z","sha256":"e3d99fa69df24bb5170c840f84e44038c20cf8b431c94abfd57eaa3701593684","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/common-fs/v/1.0.0"}],"affected":[{"package":{"name":"common-fs","ecosystem":"npm","purl":"pkg:npm/common-fs"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/common-fs/MAL-2026-17300.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"f1611cb60db31fe0bd5ab0c72e94bd05c0557cfe","sha512_sri":"sha512-gZOgk2GPU3Eh2dcdKyMOAUaakS7XykK2QCgtOI3IMR+kkMO09+rC90uDXn8X8ALyZTtzkWa7bkIF4k5+1tDv5w=="},"filename":"common-fs-1.0.0.tgz"}],"evidence_files":[{"sha256":"72a7f942cc38326c29c48b536fa49f166c8d4d544b43da66893c2e9a59fffab0","tlsh":"83f10f6c39f930248857b07c67eb9449612de0576e9a6ca87f4d83101f7d13ce1f6ba8","path":"index.js"},{"sha256":"65b54532c82855bbc8055c67d9f53854737ce01d3ae6b95fc6577204b81d953f","tlsh":"4e331f3acb780c5b91795a606af50a4af280471f17a16d877fbcd54c8fb1c5b804ab3b","path":"use.js"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}