{"id":"MAL-2026-17418","summary":"Malicious code in future-scripts (npm)","details":"On October 10, 2026 (local time), boom() calls localStorage.setItem('key', i) 100,000,000 times in a synchronous loop, potentially freezing a browser page. In version 0.0.2, the exported getCommonDateInRanges() calls boom() before input validation; the bundled source map confirms this path. Version 0.0.3 retains boom() as a separate export but no longer calls it from getCommonDateInRanges(), so an explicit call is required. Version 0.0.1 does not contain this routine. This is a static finding; actual victim impact was not observed.","modified":"2026-10-01T05:45:04.199145766Z","published":"2026-09-30T00:13:16Z","affected":[{"package":{"name":"future-scripts","ecosystem":"npm","purl":"pkg:npm/future-scripts"},"versions":["0.0.2","0.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-400","description":"The product does not properly control the allocation and maintenance of a limited resource.","name":"Uncontrolled Resource Consumption"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/future-scripts/MAL-2026-17418.json"}}],"schema_version":"1.9.0","credits":[{"name":"ESTsecurity","type":"FINDER"}]}