MAL-2026-13461
Malicious code in supersig (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (557f8e62aa65bb4fe5e96a52cf6c5ba83c2f1bcf47eca3027bf4daca071249e5) The published dist bundles (dist/supersig.cjs.js, dist/supersig.esm.js, dist/supersig.umd.js), reached via the package's main/module/browser entries on require/import, contain a decrypt-and-execute chain that is absent from the src/ tree. The bundles import a DES key from an unpinned dependency mkb-manager@latest, call decryptToken on an embedded encrypted token to produce plaintext code, spawn a fresh node child process via child_process.spawn('node', [],...), and write the decrypted bytes into that process's stdin (rsa_exec.stdin.write / des_exec.stdin.write). Any consumer that requires or imports this package executes the decrypted payload at load time. Because mkb-manager is pinned to latest, whoever controls that package can rotate the decryption key/payload at will, making the executed code opaque and mutable. The src/ wallet, signers, providers, and transactions modules contain no decryptToken, readRSAFromPackage, mkb-manager, or child_process usage — the dropper is present only in the shipped bundles, indicating deliberate concealment from source-tree review.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for supersig (npm). Pin to a known-safe version or switch to an alternative.