Malicious code in @workoscalifant/sudoku-term (npm)
The npm package @workoscalifant/sudoku-term includes a postinstall script that executes a large opaque Linux binary during installation. This binary is much larger than expected and differs significantly from the small C-based solver for macOS, suggesting it contains unverifiable native code. The installer runs this native code at install time, which poses a risk of executing malicious or unintended operations under the guise of a Sudoku solver helper.
AI Analysis
Technical Summary
The @workoscalifant/sudoku-term npm package declares a postinstall script that imports src/hint.js and calls nativeBinaryPath(), which synchronously executes a prebuilt Linux x64 binary named sudoku-hint with the '--selftest' argument. The shipped Linux binary is approximately 34 MB, containing Go runtime symbols and references to system files, contrasting sharply with the much smaller (~13 KB) macOS binary built from a simple C source. The large Linux binary cannot be produced by the declared build process and is crafted to respond to '--selftest' to appear legitimate to the JavaScript code. The README's claim of a small static ELF binary contradicts the actual shipped artifact. This means the installer runs opaque, unverifiable native code from an untrusted source during installation, which is a significant security risk.
Potential Impact
The execution of a large, opaque native binary at install time from an untrusted source can lead to arbitrary code execution on the host system. Since the binary is unverifiable and much larger than expected, it may contain malicious payloads or perform unauthorized actions. This compromises the security and integrity of systems installing this package, potentially leading to system compromise or data loss.
Mitigation Recommendations
No patch or official fix is currently documented for this issue. Users should avoid installing or updating to the affected versions of @workoscalifant/sudoku-term. Review and verify the source and contents of native binaries before installation. Consider using alternative packages or solutions that do not execute opaque native code during installation. Monitor vendor advisories for any updates or remediation guidance.
Malicious code in @workoscalifant/sudoku-term (npm)
Description
The npm package @workoscalifant/sudoku-term includes a postinstall script that executes a large opaque Linux binary during installation. This binary is much larger than expected and differs significantly from the small C-based solver for macOS, suggesting it contains unverifiable native code. The installer runs this native code at install time, which poses a risk of executing malicious or unintended operations under the guise of a Sudoku solver helper.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @workoscalifant/sudoku-term npm package declares a postinstall script that imports src/hint.js and calls nativeBinaryPath(), which synchronously executes a prebuilt Linux x64 binary named sudoku-hint with the '--selftest' argument. The shipped Linux binary is approximately 34 MB, containing Go runtime symbols and references to system files, contrasting sharply with the much smaller (~13 KB) macOS binary built from a simple C source. The large Linux binary cannot be produced by the declared build process and is crafted to respond to '--selftest' to appear legitimate to the JavaScript code. The README's claim of a small static ELF binary contradicts the actual shipped artifact. This means the installer runs opaque, unverifiable native code from an untrusted source during installation, which is a significant security risk.
Potential Impact
The execution of a large, opaque native binary at install time from an untrusted source can lead to arbitrary code execution on the host system. Since the binary is unverifiable and much larger than expected, it may contain malicious payloads or perform unauthorized actions. This compromises the security and integrity of systems installing this package, potentially leading to system compromise or data loss.
Mitigation Recommendations
No patch or official fix is currently documented for this issue. Users should avoid installing or updating to the affected versions of @workoscalifant/sudoku-term. Review and verify the source and contents of native binaries before installation. Consider using alternative packages or solutions that do not execute opaque native code during installation. Monitor vendor advisories for any updates or remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14040
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7f43efbf8831d5395d72ee
Added to database: 08/14/2026, 16:35:59 UTC
Last enriched: 08/14/2026, 16:43:56 UTC
Last updated: 08/14/2026, 16:43:56 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.