npm

path-internal @1.0.15

Vulnerability report · Last retrieved from osv.dev July 13, 2026 at 6:40 AM UTC

Malicious

OSV ID

MAL-2026-2930

Ecosystem

npm

Summary

The package presents itself as a copy of the Node.js core path module (name path-internal , README: "exact copy of the NodeJS 'path' module") and ships the upstream Joyent path implementation with a malicious dropper spliced between posix.basename and posix.extname in path.js . On require('path-internal') , the module decodes a base64-encoded URL ( https://www.jsonkeeper.com/b/YCW2F , stored under the misleading variable name randomStringRe ), fetches the JSON document at that URL, and passes data.content straight to eval() . A second identical IIFE for https://www.jsonkeeper.com/b/TPQHE is present (commented out) under tokenStringRe . jsonkeeper.com is an anonymous, mutable paste host: the attacker can change the served payload at any time to execute arbitrary code in-process on every installer that imports the package. The base64 obfuscation, the regex-shaped decoy variable names, the splice into a verbatim copy of a Node stdlib module, and the typosquat name (with the README also confusingly suggesting npm install --save path-external ) collectively confirm malicious intent rather than negligence.

Source: amazon-inspector (5393cf6d8cf49c2550e7cc90ff3de58b1e97bdc89183f63beae60b3e46b9d2e0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.