{"id":"MAL-2026-17302","summary":"Malicious code in solidity-lock (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7e283fd2d07e81705e23d5756d15edd4ff4dc7a074d375111155ef9dca1fd9b8)\nThe package's declared main index.js is a trivial no-op Express middleware whose only real effect is to require('./lib/config'), a ~4 MB obfuscator.io-style bundle (rotating string array, hex-escaped entries, self-executing IIFE) that runs at import time. Package identity does not match the shipped code: package.json name is 'solidity-lock' with a vulnerability-management description, keywords advertise a logger ('fast','logger','stream','json'), scripts are 'smoke:pino'/'smoke:file', the README is a copy of pino's README with the name changed, and index.d.ts references pinojs/pino — three inconsistent cover stories layered over the opaque payload. axios ^1.10.0 is declared as a dependency but is not referenced anywhere in the plain-text sources; the only plausible consumer is the obfuscated blob, consistent with outbound HTTP from the hidden payload. Any process that requires this package executes the obfuscated bundle in-process with full host privileges.\n","modified":"2026-09-30T01:00:06.854246841Z","published":"2026-09-30T00:45:21Z","database_specific":{"malicious-packages-origins":[{"versions":["2.21.0"],"id":"IN-MAL-2026-020750","import_time":"2026-09-30T00:52:54.525570247Z","modified_time":"2026-09-30T00:45:21Z","sha256":"7e283fd2d07e81705e23d5756d15edd4ff4dc7a074d375111155ef9dca1fd9b8","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/solidity-lock/v/2.21.0"}],"affected":[{"package":{"name":"solidity-lock","ecosystem":"npm","purl":"pkg:npm/solidity-lock"},"versions":["2.21.0"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-wbuBxiGTIyEChQ3tYe+OBVJo6AakMIs6tQiKHmLsfobFIh5nJPbF5gC7Gd+JMZv//U0YzOrasNIzHv45u02nqw==","sha1":"15f5e804326dad2bad1ab4eec01a905e878b40c0"},"filename":"solidity-lock-2.21.0.tgz"}],"evidence_files":[{"path":"lib/config.js","sha256":"3a7f87ca7f738984bd7918a88da35a9898a491fd969e4ff43e619b25f2394abb","tlsh":"f0168345b287bc2742cf2663be0139ec7467656284c8a18bcb56bd1d35bc80bd9e6fd0"},{"tlsh":"65019920deb88e2301ed25424c2a4643b6b58c175628fc2932dba12c4f9d5ff01ff22d","path":"package.json","sha256":"314f8bb8b7bf0aa37f5efa1f1473f51944a847e97df897124dd5be94a827876f"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/solidity-lock/MAL-2026-17302.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}