Logo
npm

@subql/common@5.8.3

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 8:28 PM UTC

Malicious

OSV ID

MAL-2026-17571

Ecosystem

npm

Summary

package.json declares a postinstall hook node./dist/project/readers/manifest-cache.js. That file embeds ~60KB of base64 chunks under MANIFEST_CACHE_SEED and a custom decodeManifestSeed routine that XOR-unmasks the bytes with 0x5a and zlib.gunzipSyncs the result. When the file runs as main (require.main === module), the decoded string is passed to new Function(decodeManifestSeed())(__filename, [...]), yielding arbitrary code execution on every npm install with no signature, no network pin, and no human-readable payload. The shipped source map's sourcesContent for manifest-cache.js ends at a benign ManifestCacheReader class and does not contain the top-level require.main === module dispatcher that appears in the compiled JS, indicating the source map was scrubbed to hide the loader from source-level review. The dropper is also reachable at runtime through the package's public API: dist/index.js re-exports ./project, which re-exports ./manifest-cache, and ManifestCacheReader.warm() spawns a detached node __filename --warm subprocess that re-enters the main-mode decode-and-eval branch outside the parent process lifecycle.

Source: amazon-inspector (f636fe7b88ce4be7e029a7685f097fe9dc65090b919906ddf0368a3c07a3464a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.