st-bigintr@5.0.5
Malicious code in st-bigintr (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
Combosquat of the big.js arbitrary-precision decimal arithmetic library. The package name st-bigintr impersonates the legitimate big.js on npm. It ships an otherwise unmodified copy of big.js but injects a try/catch block at the end of big.js and big.mjs that loads and executes a known-malicious dependency (sjs-builder) via require() at runtime. The malicious code runs when the library is imported — no install hook needed. The package manifest falsely claims the original big.js author, repository, and GitHub URL to appear legitimate.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 06:48 AM
- analyzed
- Jun 14, 2026, 06:48 AM
Related advisories
- stacknova@1.0.0
- sqrt-bn-enhanced@2.0.9
- spectral-corsair@999.999.1000
- sort-destructure-keys@7.9.0
- sort-btree@2.1.4
- solana-token-api@1.0.0
- solanarpclampweb3@1.0.3
- snavbox@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.