LWA-2026-5189 MAL-2026-6880 ↗ confirmed malware

st-biginteger@5.0.5

Malicious code in st-biginteger (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

st-biginteger is a combosquat of the legitimate big.js arbitrary-precision decimal arithmetic library. The package ships a clean copy of big.js source but declares a dependency on sjs-builders (a known-malicious package). When installed, sjs-builders' postinstall hook executes heavily obfuscated JavaScript (javascript-obfuscator style with dictionary-array decoding) that runs arbitrary payload. This is a dependency-chain supply-chain attack: the combosquat appears legitimate at first glance (same README, repo URL, and source as the real library) but silently introduces malware through its dependency tree.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 06:48 AM
analyzed
Jun 14, 2026, 06:49 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.