st-biginteger@5.0.5
Malicious code in st-biginteger (npm)
Analysis
st-biginteger is a combosquat of the legitimate big.js arbitrary-precision decimal arithmetic library. The package ships a clean copy of big.js source but declares a dependency on sjs-builders (a known-malicious package). When installed, sjs-builders' postinstall hook executes heavily obfuscated JavaScript (javascript-obfuscator style with dictionary-array decoding) that runs arbitrary payload. This is a dependency-chain supply-chain attack: the combosquat appears legitimate at first glance (same README, repo URL, and source as the real library) but silently introduces malware through its dependency tree.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 06:48 AM
- analyzed
- Jun 14, 2026, 06:49 AM
Related advisories
- st-bigintr@5.0.5
- stacknova@1.0.0
- sqrt-bn-enhanced@2.0.9
- spectral-corsair@999.999.1000
- sort-destructure-keys@7.9.0
- sort-btree@2.1.4
- solana-token-api@1.0.0
- solanarpclampweb3@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.