{"id":"MAL-2026-6368","summary":"Malicious code in decimal-format-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (864677541e3090100ca588a37d8eb525f74817ade2fce5cb3e265af45b0c4e9a)\nThe postinstall script scripts/sync-peer.cjs runs `npm pack decimal-format-utils@1.0.1` (or whatever version is configured via BACKUP_TARGET_VERSION/BACKUP_PAYLOAD_SPEC), extracts the resulting tarball, overwrites every file of the installed v1.0.0 package in place via fs.cpSync over the package root, and then require()s the replaced index.js and awaits from_str(). The effect is that `npm install decimal-format-utils@1.0.0` executes code from a different, publisher-mutable version at install time, bypassing lockfile pinning and giving the publisher a live remote code execution channel into every install. The package additionally impersonates the big.js maintainer: package.json sets `author: Michael Mclaughlin` and `repository.url: https://github.com/MikeMcl/big.js.git`, and the README falsely claims the package is pulled in automatically as a dependency of big.js@6.2.x. big.js declares no such dependency. The impersonation appears designed to lure installers into trusting an unrelated publisher whose postinstall then executes arbitrary fetched code.\n","modified":"2026-06-24T05:01:22.572133151Z","published":"2026-06-24T03:59:39Z","database_specific":{"malicious-packages-origins":[{"sha256":"864677541e3090100ca588a37d8eb525f74817ade2fce5cb3e265af45b0c4e9a","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-007417","import_time":"2026-06-24T04:54:33.883195414Z","modified_time":"2026-06-24T03:59:39Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/decimal-format-utils/v/1.0.0"}],"affected":[{"package":{"name":"decimal-format-utils","ecosystem":"npm","purl":"pkg:npm/decimal-format-utils"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/sync-peer.cjs","sha256":"213b589b069ddac2d3321b821e6337146a01d8743c67e4718bdf930b95e8c6e7","tlsh":"3f51f18916d317708bb297e55b2a102eb9ba84233241a7b1b6cca0c12fb55314316efd"},{"path":"package.json","sha256":"12ea27fe474c67a40b17c5a5dd81136a2ba8651beb05ac9aaad570162f905366","tlsh":"56017b33de509c2759b89a6abdac4216b2520f1f11704c47b0fb511c8bb366714bab3d"}],"package_integrity":[{"filename":"decimal-format-utils-1.0.0.tgz","hashes":{"sha1":"1805b644c59273385ea94c304ced9d5bdf0ce1a2","sha512_sri":"sha512-4Eah0MCKkP8gcCgeK3iGtwrccbvCwuUC9/ur0V2q85rgxhSZ6JdRQvhdgx2D5oyG0lJEKgY1aiwQ+xOhILVzJw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/decimal-format-utils/MAL-2026-6368.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}