solidity-lock@2.21.0
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17302
Ecosystem
npm
Summary
The package's declared main index.js is a trivial no-op Express middleware whose only real effect is to require('./lib/config'), a ~4 MB obfuscator.io-style bundle (rotating string array, hex-escaped entries, self-executing IIFE) that runs at import time. Package identity does not match the shipped code: package.json name is 'solidity-lock' with a vulnerability-management description, keywords advertise a logger ('fast','logger','stream','json'), scripts are 'smoke:pino'/'smoke:file', the README is a copy of pino's README with the name changed, and index.d.ts references pinojs/pino — three inconsistent cover stories layered over the opaque payload. axios ^1.10.0 is declared as a dependency but is not referenced anywhere in the plain-text sources; the only plausible consumer is the obfuscated blob, consistent with outbound HTTP from the hidden payload. Any process that requires this package executes the obfuscated bundle in-process with full host privileges.
Source: amazon-inspector (7e283fd2d07e81705e23d5756d15edd4ff4dc7a074d375111155ef9dca1fd9b8)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.