{"id":"MAL-2026-17312","summary":"Malicious code in json-bigint-rs (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7f5b71b917a0504deb87a597d9d07527179c2d6bb9ec1f836caa34d6145aa043)\nOn require(), index.js instantiates the shipped json-bigint-rs.wasm module and, for imports declared under the 'wasm:js/string-constants' module namespace, exposes each descriptor's name as an externref global. This mechanism smuggles a full JavaScript payload as WASM import-descriptor names, hiding it from JS-only source scanners. The reconstructed payload is an IIFE wired to node:vm.runInThisContext / runInNewContext that polls three hardcoded hosts (rs.undotest.top, rs.lightnight.top, rs.belivelight.top) every 30 seconds and executes the response body as JavaScript in-process with access to console and process. Execution is gated by NODE_ENV==='production', so the dropper stays dormant on developer machines and activates on servers and CI. The remote hosts are mutable and unrelated to any documented publisher; the behavior is undocumented in README. The package name and stated purpose (a bignum JSON parser) provide cover for a delivery vehicle whose only observable install/require-time effect is fetching and evaluating attacker-chosen JavaScript.\n","modified":"2026-09-30T03:00:04.414213182Z","published":"2026-09-30T01:47:59Z","database_specific":{"malicious-packages-origins":[{"versions":["0.1.1"],"id":"IN-MAL-2026-020793","import_time":"2026-09-30T02:52:56.882168345Z","modified_time":"2026-09-30T01:47:59Z","sha256":"7f5b71b917a0504deb87a597d9d07527179c2d6bb9ec1f836caa34d6145aa043","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/json-bigint-rs/v/0.1.1"}],"affected":[{"package":{"name":"json-bigint-rs","ecosystem":"npm","purl":"pkg:npm/json-bigint-rs"},"versions":["0.1.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"json-bigint-rs.wasm","sha256":"d040c3632590b3c2199c0d737aff07e9310b2e182328759d4722adc24572e90b","tlsh":"64a2d707b52f24acb341a4360a5985363b5f0c40f169a6b2f74d647a6fffa19b4d3b20"},{"tlsh":"d491870e7df2e09146e3a2a49c5b941925388121b038edeaf5ec43d42fd1569cbb6fcd","path":"index.js","sha256":"83cc133b5ef9e956ebe9ca7faa4d5e893b958fa51f0548b59d81092b7a7977f5"}],"package_integrity":[{"filename":"json-bigint-rs-0.1.1.tgz","hashes":{"sha512_sri":"sha512-ezvCHb2kJ6IBmGnYSerUSDoBiQzGBzI/7sREGzeRl7oRNP83HFQDWNgPGb+4uz3ZavQ4mTxMRiOreZS7ggeLkw==","sha1":"7098a869051bad5c71d5d2bf04a798df0c4be16f"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/json-bigint-rs/MAL-2026-17312.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}