CRITICAL npm Malware

Malicious code in localization-fixer (npm)

MAL-2026-13631

Published · Modified

Description


__

Source: amazon-inspector (72446c1307e81047c64d819d3485fa77062061c8c9d4d0b38b42e311137c8701)

On require of the package's main entry, a top-level if (isServer) syncLanguageSystem() fetches a JSON payload from https://api.jsonbin.io/v3/b/6a764665da38895dfec7cd5d and executes the returned record.value field as JavaScript, both by writing it to a temp file and running it via child_process.fork and via new Function('require', payload)(require) in a separate module-load IIFE that pulls https://api.jsonbin.io/v3/b/6a718a58da38895dfeb6e2ed. Both sinks pass the Node require to the constructed function, granting full Node capabilities to whatever the mutable jsonbin.io bin currently serves. Function and variable names (syncLanguageSystem, LANG_SOURCE, lang_pass_key) frame the fetch-and-exec as a localization-sync feature, but the advertised purpose of the package has no need to evaluate remote bytes. The jsonbin.io bins are attacker-mutable, so the payload delivered to any installer is arbitrary and can change at any moment.

Ready to move

Start Securing

Free, no credit card | First findings in minutes