common-fs@1.0.0
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17300
Ecosystem
npm
Summary
common-fs advertises itself as a filesystem/transaction helper but ships an obfuscated code loader. index.js reconstructs the identifiers 'Function', 'Buffer', 'require', 'process', and 'setTimeout' from a shuffled string-array and obtains the Function constructor indirectly via global.constructor.constructor, hiding the eval sink from casual review. The documented getTransactions() entry point calls load_transaction_data(), which reads the sibling file use.js, treats it as a product catalog, concatenates the per-entry 'mark' fields in id order, applies a base64 + Caesar-shift decode followed by another base64 decode, and executes the resulting bytes with the Function constructor while injecting Buffer, require, and process. use.js is not data; it is the payload container, split across many small 'mark' fields to defeat string search. The moment a consumer calls the library's advertised API, attacker-controlled JavaScript runs in the caller's process with full access to require and process — enabling arbitrary code execution, filesystem access, and network exfiltration on the installer's host.
Source: amazon-inspector (e3d99fa69df24bb5170c840f84e44038c20cf8b431c94abfd57eaa3701593684)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.