npm

supersig @1.0.5

Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 4:15 AM UTC

Malicious

OSV ID

MAL-2026-13461

Ecosystem

npm

Summary

The published dist bundles (dist/supersig.cjs.js, dist/supersig.esm.js, dist/supersig.umd.js), reached via the package's main/module/browser entries on require/import, contain a decrypt-and-execute chain that is absent from the src/ tree. The bundles import a DES key from an unpinned dependency mkb-manager@latest, call decryptToken on an embedded encrypted token to produce plaintext code, spawn a fresh node child process via child_process.spawn('node', [],...), and write the decrypted bytes into that process's stdin (rsa_exec.stdin.write / des_exec.stdin.write). Any consumer that requires or imports this package executes the decrypted payload at load time. Because mkb-manager is pinned to latest, whoever controls that package can rotate the decryption key/payload at will, making the executed code opaque and mutable. The src/ wallet, signers, providers, and transactions modules contain no decryptToken, readRSAFromPackage, mkb-manager, or child_process usage — the dropper is present only in the shipped bundles, indicating deliberate concealment from source-tree review.

Source: amazon-inspector (557f8e62aa65bb4fe5e96a52cf6c5ba83c2f1bcf47eca3027bf4daca071249e5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.