Logo
npm

fs-commons@1.0.1

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17301

Ecosystem

npm

Summary

The package presents itself as a filesystem/data-helper library, but its exported getTransactions()/load_transaction_data() functions are a two-file dynamic-code loader. index.js hides the identifiers 'Function', 'require', 'process', 'Buffer', and 'setTimeout' behind a split-string array and obtains the Function constructor indirectly via globalThis.constructor.constructor, defeating static review. At call time it reads the sibling file models.js, which is disguised as an array of product-record objects but whose mark fields are base64 ciphertext. loadConfig()/processData() sort the records by id, concatenate every mark, apply a per-count Caesar shift, base64-decode the result, and pass the resulting source to the Function constructor with Buffer, require, and process injected, then invoke it. Any consumer that requires fs-commons and calls getTransactions() executes attacker-supplied code with full Node privileges on the host process. The obfuscation, the indirect Function-constructor acquisition, and the disguising of the payload as product metadata in a sibling file have no legitimate purpose for a data-helper library and are the fingerprint of a supply-chain remote-code-execution package.

Source: amazon-inspector (f7e82e98343807c39ea786017de4d2a7455815424155ca2a856333d895c8a48b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.