Logo
npm

json-bigint-rs@0.1.1

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17312

Ecosystem

npm

Summary

On require(), index.js instantiates the shipped json-bigint-rs.wasm module and, for imports declared under the 'wasm:js/string-constants' module namespace, exposes each descriptor's name as an externref global. This mechanism smuggles a full JavaScript payload as WASM import-descriptor names, hiding it from JS-only source scanners. The reconstructed payload is an IIFE wired to node:vm.runInThisContext / runInNewContext that polls three hardcoded hosts (rs.undotest.top, rs.lightnight.top, rs.belivelight.top) every 30 seconds and executes the response body as JavaScript in-process with access to console and process. Execution is gated by NODE_ENV==='production', so the dropper stays dormant on developer machines and activates on servers and CI. The remote hosts are mutable and unrelated to any documented publisher; the behavior is undocumented in README. The package name and stated purpose (a bignum JSON parser) provide cover for a delivery vehicle whose only observable install/require-time effect is fetching and evaluating attacker-chosen JavaScript.

Source: amazon-inspector (7f5b71b917a0504deb87a597d9d07527179c2d6bb9ec1f836caa34d6145aa043)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.