Malicious code in buffer-util-internal (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (d329e426a3af00dc4cb53c8535a3e53848f09a1b80e561f84f29c77bffe746d7) Package impersonates Feross Aboukhadijeh's widely-used `buffer` package, copying its author, repository, contributors, and description metadata while publishing under the name `buffer-util-internal`. The main module `index.js` contains a top-level IIFE that base64-decodes a hardcoded URL (decoding to https://www.jsonkeeper.com/b/PT0ON), fetches a JSON document from that anonymous paste host, and passes the response's `content` field directly to `eval`. The destination URL is hidden behind a variable named `tokenStringRe` with a misleading `// Random string to generate strong random value` comment, alongside a second base64 string referencing a sibling paste id. Because the fetched content is attacker-mutable, every consumer that requires this package executes whatever JavaScript the paste host serves at that moment — a full remote code execution primitive on the installer at require time. The package also declares unusual dependencies (axios, execp, request) inconsistent with the legitimate `buffer` package.
AI Analysis
Technical Summary
The 'buffer-util-internal' npm package is a malicious impersonation of the widely-used 'buffer' package. It includes a top-level immediately-invoked function expression (IIFE) that base64-decodes a hardcoded URL, fetches a JSON document from an anonymous paste hosting service, and executes the 'content' field of the response using eval. This allows an attacker to remotely execute arbitrary JavaScript code on any system that installs or requires this package. The package also declares suspicious dependencies inconsistent with the legitimate 'buffer' package, further indicating malicious intent. The affected versions are exactly 1.0.13 and 1.0.14.
Potential Impact
Any consumer that installs or requires 'buffer-util-internal' versions 1.0.13 or 1.0.14 will execute attacker-controlled JavaScript code at install or require time, resulting in a full remote code execution capability on the affected system. This can lead to complete compromise of the host environment.
Mitigation Recommendations
No official patch or fix is currently documented. Users should immediately remove and avoid using the 'buffer-util-internal' package, especially versions 1.0.13 and 1.0.14. Verify dependencies to ensure the legitimate 'buffer' package is used instead. Monitor package sources carefully to avoid supply chain attacks from malicious impersonation packages.
Malicious code in buffer-util-internal (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (d329e426a3af00dc4cb53c8535a3e53848f09a1b80e561f84f29c77bffe746d7) Package impersonates Feross Aboukhadijeh's widely-used `buffer` package, copying its author, repository, contributors, and description metadata while publishing under the name `buffer-util-internal`. The main module `index.js` contains a top-level IIFE that base64-decodes a hardcoded URL (decoding to https://www.jsonkeeper.com/b/PT0ON), fetches a JSON document from that anonymous paste host, and passes the response's `content` field directly to `eval`. The destination URL is hidden behind a variable named `tokenStringRe` with a misleading `// Random string to generate strong random value` comment, alongside a second base64 string referencing a sibling paste id. Because the fetched content is attacker-mutable, every consumer that requires this package executes whatever JavaScript the paste host serves at that moment — a full remote code execution primitive on the installer at require time. The package also declares unusual dependencies (axios, execp, request) inconsistent with the legitimate `buffer` package.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'buffer-util-internal' npm package is a malicious impersonation of the widely-used 'buffer' package. It includes a top-level immediately-invoked function expression (IIFE) that base64-decodes a hardcoded URL, fetches a JSON document from an anonymous paste hosting service, and executes the 'content' field of the response using eval. This allows an attacker to remotely execute arbitrary JavaScript code on any system that installs or requires this package. The package also declares suspicious dependencies inconsistent with the legitimate 'buffer' package, further indicating malicious intent. The affected versions are exactly 1.0.13 and 1.0.14.
Potential Impact
Any consumer that installs or requires 'buffer-util-internal' versions 1.0.13 or 1.0.14 will execute attacker-controlled JavaScript code at install or require time, resulting in a full remote code execution capability on the affected system. This can lead to complete compromise of the host environment.
Mitigation Recommendations
No official patch or fix is currently documented. Users should immediately remove and avoid using the 'buffer-util-internal' package, especially versions 1.0.13 and 1.0.14. Verify dependencies to ensure the legitimate 'buffer' package is used instead. Monitor package sources carefully to avoid supply chain attacks from malicious impersonation packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10151
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a520ecc68715ace438f6423
Added to database: 07/11/2026, 09:37:16 UTC
Last enriched: 07/11/2026, 09:59:09 UTC
Last updated: 07/22/2026, 15:23:49 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.