Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @jaymara/jsononifier (npm)

0
Critical
Published: 07/10/2026 (07/10/2026, 21:29:35 UTC)
Source: GCVE Database
Product: @jaymara/jsononifier

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (ade6fb9a07c6f1417e9569af48b6c638bf12fba7540493b1b38a2d6ba42d101c) @jaymara/[email protected] is advertised as a JSON formatting utility but ships a covert command-execution primitive that fires on require. index.js loads trigger.js, which checks for sandbox indicators (process.env.CI==='true', NODE_ENV==='test', existence of /.dockerenv) and the platform (win32); when those checks indicate a real Windows workstation, it schedules Executer.js via process.nextTick + setTimeout(5000). Executer.js XOR-decodes a byte array from payload.js using key 'xorkey123' and passes the resulting string to child_process.exec with { windowsHide: true }. payload.js openly comments the intent ('XOR-encoded command – not visible in source'). The current decoded value is a demo (calc.exe), but the mechanism — opaque encoded bytes decoded at runtime and handed to exec, gated to skip CI/test/Docker and only fire on real victim machines — is the attack: a future tarball can swap the byte array for any command without changing the visible code. None of this is required by, or consistent with, a JSON formatter.

Affected software

npmghsa
@jaymara/jsononifier
Affected versions
=1.0.0=1.0.2=1.0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/11/2026, 09:46:08 UTC

Technical Analysis

@jaymara/jsononifier versions 1.0.0, 1.0.1, and 1.0.2 include a hidden command execution backdoor triggered upon requiring the package. The index.js loads trigger.js, which checks environment variables and platform to avoid execution in CI, test, or Docker environments, and only activates on Windows workstations. It schedules Executer.js to decode an XOR-encoded command from payload.js and executes it with Windows process hiding enabled. The current payload launches calc.exe as a demonstration, but the encoded payload can be replaced to run arbitrary commands. This behavior is unrelated to the package's advertised JSON formatting functionality, indicating malicious intent.

Potential Impact

The malicious code allows arbitrary command execution on Windows systems that import this package, potentially enabling attackers to run any commands with the privileges of the importing process. Although the current payload is benign (launching calc.exe), the mechanism can be modified to execute harmful commands, leading to system compromise, data theft, or further malware deployment. The code avoids execution in sandboxed or CI environments, increasing the risk of undetected exploitation on real victim machines.

Mitigation Recommendations

No official patch or remediation is currently available. Users should immediately remove and avoid using @jaymara/jsononifier versions 1.0.0, 1.0.1, and 1.0.2. Audit dependencies for this package and replace it with a trusted alternative. Monitor for any unexpected child process executions on Windows systems that import this package. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10177
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a520eaa68715ace438f49a6

Added to database: 07/11/2026, 09:36:42 UTC

Last enriched: 07/11/2026, 09:46:08 UTC

Last updated: 07/22/2026, 08:20:45 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses