Malicious code in url-func-registry (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (3a4d96efb2897a3908596981acd2c0666cfd7445def91a32e02e2f95c9475ecf) [email protected] exposes a factory `createJsonService` (registered under key 'JsonS' in the public `getFunc` API) that fetches https://www.jsonkeeper.com/b/XVHGD — an anonymous, publicly-editable, author-mutable JSON hosting service — reads the `data` property from the response, and passes it to `new Function.constructor('require', data.data)` which is then invoked with the real `require` bound. This compiles and executes arbitrary JavaScript hosted at an author-controlled slug on a third-party paste service, giving whoever controls that slug full code execution in any consumer process that reaches the 'JsonS' factory. The package presents itself as a URL/singleton registry; remote code execution is not part of the documented behavior, and the `createJsonService` / 'JsonS' naming frames the sink as a benign JSON fetch. Because the payload is served from a mutable pastebin, the executed content can be swapped at any time without any package republish. The backdoor fires only when a consumer invokes the factory (not at install/import), but any downstream integration that iterates or looks up the registered factories will trigger it.
AI Analysis
Technical Summary
[email protected] exposes a factory function 'createJsonService' under the 'JsonS' key in its public API, which fetches JSON data from https://www.jsonkeeper.com/b/XVHGD, a mutable and author-controlled paste service. It extracts the 'data' property from the response and passes it to the JavaScript Function constructor with 'require' bound, enabling execution of arbitrary code hosted remotely. This design allows an attacker controlling the pastebin content to execute arbitrary code in any process that uses this factory, effectively creating a remote code execution backdoor that is not part of the documented package behavior. The malicious code only executes when the factory is invoked or enumerated, not on install or import.
Potential Impact
Any consumer process that invokes or enumerates the 'JsonS' factory in [email protected] is subject to remote code execution controlled by an attacker who can modify the payload hosted on the mutable third-party JSON hosting service. This can lead to full compromise of the affected environment. The malicious code execution is stealthy as it is triggered only on factory invocation and the payload can be changed dynamically without republishing the package.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid using url-func-registry version 1.0.4, especially any functionality invoking the 'JsonS' factory. Since the malicious payload is hosted externally and mutable, removing or replacing the package is the safest mitigation. Monitor vendor advisories for any official fixes or updates. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Malicious code in url-func-registry (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (3a4d96efb2897a3908596981acd2c0666cfd7445def91a32e02e2f95c9475ecf) [email protected] exposes a factory `createJsonService` (registered under key 'JsonS' in the public `getFunc` API) that fetches https://www.jsonkeeper.com/b/XVHGD — an anonymous, publicly-editable, author-mutable JSON hosting service — reads the `data` property from the response, and passes it to `new Function.constructor('require', data.data)` which is then invoked with the real `require` bound. This compiles and executes arbitrary JavaScript hosted at an author-controlled slug on a third-party paste service, giving whoever controls that slug full code execution in any consumer process that reaches the 'JsonS' factory. The package presents itself as a URL/singleton registry; remote code execution is not part of the documented behavior, and the `createJsonService` / 'JsonS' naming frames the sink as a benign JSON fetch. Because the payload is served from a mutable pastebin, the executed content can be swapped at any time without any package republish. The backdoor fires only when a consumer invokes the factory (not at install/import), but any downstream integration that iterates or looks up the registered factories will trigger it.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
[email protected] exposes a factory function 'createJsonService' under the 'JsonS' key in its public API, which fetches JSON data from https://www.jsonkeeper.com/b/XVHGD, a mutable and author-controlled paste service. It extracts the 'data' property from the response and passes it to the JavaScript Function constructor with 'require' bound, enabling execution of arbitrary code hosted remotely. This design allows an attacker controlling the pastebin content to execute arbitrary code in any process that uses this factory, effectively creating a remote code execution backdoor that is not part of the documented package behavior. The malicious code only executes when the factory is invoked or enumerated, not on install or import.
Potential Impact
Any consumer process that invokes or enumerates the 'JsonS' factory in [email protected] is subject to remote code execution controlled by an attacker who can modify the payload hosted on the mutable third-party JSON hosting service. This can lead to full compromise of the affected environment. The malicious code execution is stealthy as it is triggered only on factory invocation and the payload can be changed dynamically without republishing the package.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid using url-func-registry version 1.0.4, especially any functionality invoking the 'JsonS' factory. Since the malicious payload is hosted externally and mutable, removing or replacing the package is the safest mitigation. Monitor vendor advisories for any official fixes or updates. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10108
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a50ba4168715ace4357e314
Added to database: 07/10/2026, 09:24:17 UTC
Last enriched: 07/10/2026, 09:35:11 UTC
Last updated: 07/26/2026, 14:51:31 UTC
Views: 22
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.