Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @workoscalifant/sudoku-term (npm)

0
High
Published: 08/14/2026 (08/14/2026, 15:06:20 UTC)
Source: GCVE Database
Product: @workoscalifant/sudoku-term

Description

The npm package @workoscalifant/sudoku-term includes a postinstall script that executes a large opaque Linux binary during installation. This binary is much larger than expected and differs significantly from the small C-based solver for macOS, suggesting it contains unverifiable native code. The installer runs this native code at install time, which poses a risk of executing malicious or unintended operations under the guise of a Sudoku solver helper.

Affected software

npmghsa
@workoscalifant/sudoku-term
Affected versions
=1.1.4=1.1.5=1.1.3=1.1.1=1.1.7=1.1.2=1.1.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 16:43:56 UTC

Technical Analysis

The @workoscalifant/sudoku-term npm package declares a postinstall script that imports src/hint.js and calls nativeBinaryPath(), which synchronously executes a prebuilt Linux x64 binary named sudoku-hint with the '--selftest' argument. The shipped Linux binary is approximately 34 MB, containing Go runtime symbols and references to system files, contrasting sharply with the much smaller (~13 KB) macOS binary built from a simple C source. The large Linux binary cannot be produced by the declared build process and is crafted to respond to '--selftest' to appear legitimate to the JavaScript code. The README's claim of a small static ELF binary contradicts the actual shipped artifact. This means the installer runs opaque, unverifiable native code from an untrusted source during installation, which is a significant security risk.

Potential Impact

The execution of a large, opaque native binary at install time from an untrusted source can lead to arbitrary code execution on the host system. Since the binary is unverifiable and much larger than expected, it may contain malicious payloads or perform unauthorized actions. This compromises the security and integrity of systems installing this package, potentially leading to system compromise or data loss.

Mitigation Recommendations

No patch or official fix is currently documented for this issue. Users should avoid installing or updating to the affected versions of @workoscalifant/sudoku-term. Review and verify the source and contents of native binaries before installation. Consider using alternative packages or solutions that do not execute opaque native code during installation. Monitor vendor advisories for any updates or remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14040
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7f43efbf8831d5395d72ee

Added to database: 08/14/2026, 16:35:59 UTC

Last enriched: 08/14/2026, 16:43:56 UTC

Last updated: 08/14/2026, 16:43:56 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses