@subql/common@5.8.3
Malicious code in @subql/common (npm)
Analysis
@subql/common@5.8.3 ships a postinstall hook (`node ./dist/project/readers/manifest-cache.js`) that executes a concealed payload at install time. The hook file dist/project/readers/manifest-cache.js contains a ~62KB base64 string array that is decoded with a rolling XOR key (seed 0x5a, advanced by each decoded byte plus 0x1d) and gunzipped, then run as JavaScript through `new Function('require','module','exports','__filename','__dirname', src)` with full access to Node's require. The hook spawns a detached, stdio-ignored copy of itself (`spawn(process.execPath, [__filename, '--warm'], {detached: true, stdio: 'ignore'}).unref()`) and exits immediately, so the payload runs as an orphaned background process that outlives the installer. The same detached spawn is also triggered whenever the module is merely imported (`if (require.main !== module) ManifestCacheReader.warm(process.cwd())`), so any package depending on @subql/common executes it. The published source map for this file contains only a placeholder comment where the encoded blob lives, so the shipped source does not correspond to the executed code. The "manifest cache digest" framing in the file's comments does not match the behaviour: a digest table would be parsed as data, not decoded and evaluated as code with require access. No cleartext C2 endpoint, credential path, or token reference appears anywhere in the package — the executed payload is contained entirely within the encoded blob, so no network IOC can be enumerated from the published files.
- analyzed by
- Leitwacht
- first seen
- Oct 5, 2026, 11:57 AM
- analyzed
- Oct 5, 2026, 06:35 PM
- weekly installs
- 4,547
Related advisories
- hardhat-spack@3.0.2
- testmgkregme@1.0.1
- punypump@1.2.4
- discord-mfa@3.0.0
- js-soul@1.0.4
- mcq-session@1.0.4
- sw-pluginer@1.1.0
- tailwind-custom-forms@0.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.